Vatican's prayer app leaks over 700K users' personal information

www.offthepress.com

A popular Vatican website and mobile app has been leaking hundreds of thousands of users’ names and email addresses.

“Click to Pray” is the Vatican’s official prayer app. Users can sign up for access to daily prayers, and a steady stream of papal content on their phones or computers. It’s available on iOS and Android, and via a Web browser. According to its website, Click to Pray is used in more or less every country on the planet.

In January, the white hat hacker “BobDaHacker” discovered an insecure direct object reference (IDOR) vulnerability in clicktopray.org. Any passing Internet user could query a specific, totally exposed application programming interface (API) endpoint to see basic personally identifying information (PII) belonging to all of Click to Pray’s account holders, as well as active employees of the organization that runs the app, the Pope’s Worldwide Prayer Network.

More here

Tagged: Religion BACK TO HOMEPAGE