ZeroHour

CVE-2022-0732

CVSS 3.1
7.5 high
EPSS
3%p84
Published
()
Modified
Description

The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating an IDOR (Insecure Direct Object Reference) vulnerability.

Vendors
1byte
Products
copy9, exactspy, fonetracker, guestspy, ispyoo, mxspy, secondclone, the truth spy, thespyapp
Weakness
CWE-284, CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news