Vulnerabilities (CVE)

Filtered by vendor Lmsdoctor Subscribe
Filtered by product 2 Factor Authentication
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-28601 1 Lmsdoctor 1 2 Factor Authentication 2022-05-23 4.0 MEDIUM 6.5 MEDIUM
A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone number used for confirmation via the profile.php file. Therefore, allowing them to bypass the phone verification mechanism.