An issue exists in 42Gears SureMDM prior to 2018-11-27, related to CORS settings. Cross-origin access is possible.
42gears suremdm