Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pghm-m86j-5288

Опубликовано: 11 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone number used for confirmation via the profile.php file. Therefore, allowing them to bypass the phone verification mechanism.

A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone number used for confirmation via the profile.php file. Therefore, allowing them to bypass the phone verification mechanism.

EPSS

Процентиль: 90%
0.05579
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.5
nvd
больше 3 лет назад

A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone number used for confirmation via the profile.php file. Therefore, allowing them to bypass the phone verification mechanism.

EPSS

Процентиль: 90%
0.05579
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863