{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/lmsdoctor/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:lmsdoctor:2_factor_authentication:-:*:*:*:*:moodle:*:*"],"_cs_cves":[{"cvss":6.5,"id":"CVE-2022-28601"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Simple 2 Factor Authentication Plugin For Moodle"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Lmsdoctor"],"content_html":"\u003cp\u003eCVE-2022-28601 is a 2FA bypass vulnerability affecting the 'Simple 2 Factor Authentication' plugin for Moodle. The vulnerability allows a low-privileged user to exploit the plugin's profile management functionality to modify the phone number associated with an account. By overwriting the victim's legitimate phone number with an attacker-controlled number, the attacker forces the system to send the 2FA verification PIN to a device they control. This effectively grants the attacker control over the second factor of authentication, facilitating account takeover. The vulnerability exists within the plugin's handling of the \u003ccode\u003e/auth/simple2fa/profile.php\u003c/code\u003e endpoint. Although this is an older CVE, the recent publication of functional proof-of-concept (PoC) material on Sploitus necessitates immediate remediation for organizations still utilizing this specific Moodle plugin.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker authenticates to the Moodle environment using a low-privileged account via \u003ccode\u003ePOST /login/index.php\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe system triggers a 2FA challenge, expecting a PIN input via \u003ccode\u003ePOST /auth/simple2fa/confirm.php\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eInstead of completing the 2FA process, the attacker navigates to the plugin's profile management interface.\u003c/li\u003e\n\u003cli\u003eThe attacker sends a \u003ccode\u003ePOST\u003c/code\u003e request to \u003ccode\u003e/auth/simple2fa/profile.php\u003c/code\u003e to overwrite the account's associated phone number.\u003c/li\u003e\n\u003cli\u003eThe server updates the record, binding the attacker's phone number to the target user account.\u003c/li\u003e\n\u003cli\u003eThe attacker re-initiates the login process or triggers a new 2FA request.\u003c/li\u003e\n\u003cli\u003eThe system sends the 2FA PIN to the phone number updated in step 4.\u003c/li\u003e\n\u003cli\u003eThe attacker receives the PIN on their device and submits it to the portal to bypass the authentication gate.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthorized users to bypass secondary authentication, leading to full account takeover for any account targeted by an attacker. This impacts the confidentiality and integrity of educational data stored within the Moodle LMS. All versions of the Lmsdoctor 'Simple 2 Factor Authentication' plugin for Moodle are affected.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAudit Moodle server access logs for repeated \u003ccode\u003ePOST\u003c/code\u003e requests to \u003ccode\u003e/auth/simple2fa/profile.php\u003c/code\u003e by low-privileged user accounts.\u003c/li\u003e\n\u003cli\u003eDisable or uninstall the 'Simple 2 Factor Authentication' plugin for Moodle if an official patch is not available from the vendor.\u003c/li\u003e\n\u003cli\u003eImplement compensating controls such as IP-based rate limiting on the \u003ccode\u003e/auth/simple2fa/\u003c/code\u003e directory to detect and block forced browsing or automated exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T08:24:38Z","date_published":"2026-08-28T08:24:38Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2022-28601/","summary":"CVE-2022-28601 allows an authenticated low-privileged user to bypass 2FA by overwriting a target account's associated phone number via the plugin's profile management endpoint.","title":"Authentication Bypass in Simple 2 Factor Authentication Plugin for Moodle","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2022-28601/"}],"language":"en","title":"CraftedSignal Threat Feed - Lmsdoctor","version":"https://jsonfeed.org/version/1.1"}