CVE Database
/

CVE-2022-0732

Back to search

CVE-2022-0732

Published: Feb 24, 2022

Modified: Sep 16, 2024

PUBLISHED

Description

The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating an IDOR (Insecure Direct Object Reference) vulnerability.

VendorProductVersions

1Byte

Copy9

affected
All

1Byte

FoneTracker

affected
All

1Byte

iSpyoo

affected
All

1Byte

GuestSpy

affected
All

1Byte

TheSpyApp

affected
All

1Byte

ExactSpy

affected
All

1Byte

SecondClone

affected
All

1Byte

The Truth Spy

affected
All

1Byte

MxSpy

affected
All

Weaknesses (CWE)

References

VU#229438
third-party-advisory
x_refsource_CERT-VN
https://kb.cert.org/vuls/id/229438
third-party-advisory
x_refsource_CERT-VN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now