Back Scworld Vatican's 'Click to Pray' app leaks personal data of hundreds of thousands | brief
A popular Vatican website and mobile app, 'Click to Pray,' was found to be leaking the names and email addresses of hundreds of thousands of its users. The app, which provides daily prayers and papal content, is used globally. This vulnerability was discovered by a white hat hacker and confirmed by Dark Reading, based on information published by Dark Reading.
A vulnerability known as an insecure direct object reference (IDOR) was discovered in the 'Click to Pray' application programming interface (API). This flaw allows any internet user to query a specific API endpoint and access personally identifying information (PII) of account holders, including employees of the Pope's Worldwide Prayer Network. Over 700,000 user accounts are exposed, with email addresses and names leaked in plaintext. The vulnerability requires no technical skill to exploit, only a browser. Attackers could use this data for mass emailing or social engineering schemes, leveraging users' faith. The Pope's Worldwide Prayer Network, which owns the app developed by La Machi, has not yet responded to requests for . This incident highlights a common type of vulnerability, broken access control, which remains prevalent across various industries and company sizes, based on information published by Dark Reading.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
