FlaviuPopescu

3 exploits Active since Aug 2021
CVE-2022-28601 NOMISEC MEDIUM WRITEUP
Simple 2FA Plugin for Moodle - Auth Bypass
A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone number used for confirmation via the profile.php file. Therefore, allowing them to bypass the phone verification mechanism.
8 stars
CVSS 6.5
CVE-2022-28986 NOMISEC HIGH WORKING POC
LMS Doctor Simple <2021072900 - IDOR
LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to update sensitive records such as email, password and phone number of other user accounts.
2 stars
CVSS 7.5
CVE-2021-38095 WRITEUP HIGH WORKING POC
Planview Spigit 4.5.3 - Info Disclosure
The REST API in Planview Spigit 4.5.3 allows remote unauthenticated attackers to query sensitive user accounts data, as demonstrated by an api/v1/users/1 request.
CVSS 7.5