CVE-2022-0732 - CVE House
Back to Database
Status published High CVE-2022-0732

The backend infrastructure shared by multiple mobile device monitoring services...

Vulnerability Description

The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating an IDOR (Insecure Direct Object Reference) vulnerability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-0732

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Copy9, FoneTracker, iSpyoo, GuestSpy, TheSpyApp, ExactSpy, SecondClone, The Truth Spy, MxSpy
Vulnerable Versions:
All

Timeline

Official Publish: February 24th, 2022
Last Modified: September 16th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)