60
CVE-2022-0732
—CVSS 3.1
7.5 high
EPSS
3%p84
Published
()
Modified
Description
The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating an IDOR (Insecure Direct Object Reference) vulnerability.
- Vendors
- 1byte
- Products
- copy9, exactspy, fonetracker, guestspy, ispyoo, mxspy, secondclone, the truth spy, thespyapp
- Weakness
- CWE-284, CWE-639
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N