PT-2022-13397 · 1Byte · Copy9+8

Zack Whittaker

·

Published

2022-02-24

·

Updated

2023-06-27

·

CVE-2022-0732

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned.
Description The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating an Insecure Direct Object Reference (IDOR) issue. This means that the system fails to properly validate access to specific objects, potentially allowing unauthorized access or manipulation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

IDOR

Weakness Enumeration

Related Identifiers

CVE-2022-0732

Affected Products

Copy9
Exactspy
Fonetracker
Guestspy
Mxspy
Secondclone
The Truth Spy
Thespyapp
Ispyoo