7.6 High
AI Score
Confidence
High
0.002 Low
EPSS
Percentile
51.4%
The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating an IDOR (Insecure Direct Object Reference) vulnerability.
cwe.mitre.org/data/definitions/284.html
kb.cert.org/vuls/id/229438
techcrunch.com/2022/02/22/stalkerware-network-spilling-data/
www.kb.cert.org/vuls/id/229438