The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating an IDOR (Insecure Direct Object Reference) vulnerability.
- https://techcrunch.com/2022/02/22/stalkerware-network-spilling-data/
No PoCs found on GitHub currently.