← Back to CVE List

CVE-2022-28601

Published: 2022-05-10T21:15Z
Last Modified: 2024-11-21T06:57Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone number used for confirmation via the profile.php file. Therefore, allowing them to bypass the phone verification mechanism. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt