Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-28986

Опубликовано: 10 мая 2022
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to update sensitive records such as email, password and phone number of other user accounts.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:lmsdoctor:2_factor_authentication:2021072900:*:*:*:*:moodle:*:*

EPSS

Процентиль: 91%
0.06296
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to update sensitive records such as email, password and phone number of other user accounts.

EPSS

Процентиль: 91%
0.06296
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-639