Lmsdoctor's vulnerability profile centers on a two-factor authentication product, with observed disclosures clustering around authorization and access-control weaknesses including user-controlled key manipulation and improper authorization checks. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lmsdoctor over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-28986HIGH LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to upd | May 10, 2022 | 7.5 | 27 | NO | NO |
CVE-2022-28601MEDIUM A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone number used for confirmation v | May 10, 2022 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lmsdoctor.
Media articles that mention a CVE ID that affects a product developed by Lmsdoctor — matched by CVE ID, not by vendor name.