CVE-2022-0732
The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating an IDOR (Insecure Direct Object Reference) vulnerability.
Published:Feb 24, 2022
Last Modified:Nov 21, 2024
EPS:Feb 24, 2022
EPSS Score:0.00679
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
1byte
Product
Copy9
1byte
Copy9
Vendor
1byte
Product
Exactspy
1byte
Exactspy
Vendor
1byte
Product
Fonetracker
1byte
Fonetracker
Vendor
1byte
Product
Guestspy
1byte
Guestspy
Vendor
1byte
Product
Ispyoo
1byte
Ispyoo
Vendor
1byte
Product
Mxspy
1byte
Mxspy
Vendor
1byte
Product
Secondclone
1byte
Secondclone
Vendor
1byte
Product
The Truth Spy
1byte
The Truth Spy
Vendor
1byte
Product
Thespyapp
1byte
Thespyapp
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
