High severity7.5NVD Advisory· Published May 10, 2022· Updated Jul 9, 2026
CVE-2022-28986
CVE-2022-28986
Description
LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to update sensitive records such as email, password and phone number of other user accounts.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- LMS/Doctor Simple 2 Factor Authentication Plugin For Moodledescription
- Range: = 2021072900
- cpe:2.3:a:lmsdoctor:2_factor_authentication:2021072900:*:*:*:*:moodle:*:*
Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.