Vulnerability CVE-2022-0732


Published: 2022-02-24

Description:
The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating an IDOR (Insecure Direct Object Reference) vulnerability.

 References:
https://kb.cert.org/vuls/id/229438
https://techcrunch.com/2022/02/22/stalkerware-network-spilling-data/
https://cwe.mitre.org/data/definitions/284.html

Copyright 2026, cxsecurity.com

 

Back to Top