cwe.mitre.org
https://cwe.mitre.org/data/definitions/284.html CVE-2022-0732
HIGH
1byte copy9 Improper Access Control
Record summary
CVE-2022-0732 has a selected CVSS score of 7.5 (high).
Description
The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating an IDOR (Insecure Direct Object Reference) vulnerability.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 27, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
9| Product | Source | Version range | Status |
|---|---|---|---|
Copy9Browse 1Byte / Copy9 | CVE List, VulnCheck | All versions | affected |
ExactSpyBrowse 1Byte / ExactSpy | CVE List | All versions | affected |
FoneTrackerBrowse 1Byte / FoneTracker | CVE List | All versions | affected |
GuestSpyBrowse 1Byte / GuestSpy | CVE List | All versions | affected |
MxSpyBrowse 1Byte / MxSpy | CVE List | All versions | affected |
SecondCloneBrowse 1Byte / SecondClone | CVE List | All versions | affected |
The Truth SpyBrowse 1Byte / The Truth Spy | CVE List | All versions | affected |
TheSpyAppBrowse 1Byte / TheSpyApp | CVE List | All versions | affected |
iSpyooBrowse 1Byte / iSpyoo | CVE List | All versions | affected |
References
5kb.cert.orgThird-party advisory
https://kb.cert.org/vuls/id/229438 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-0732 techcrunch.comConfirmation
https://techcrunch.com/2022/02/22/stalkerware-network-spilling-data VU#229438Third-party advisory
https://www.kb.cert.org/vuls/id/229438