Application security, Privacy

Vatican’s ‘Click to Pray’ app leaks personal data of hundreds of thousands

Phishing, mobile phone hacker or cyber scam concept. Password and login pass code in smartphone. Online security threat and fraud. Female scammer with cellphone and laptop. Bank account security.

A popular Vatican website and mobile app, 'Click to Pray,' was found to be leaking the names and email addresses of hundreds of thousands of its users. The app, which provides daily prayers and papal content, is used globally. This vulnerability was discovered by a white hat hacker and confirmed by Dark Reading, based on information published by Dark Reading.

A vulnerability known as an insecure direct object reference (IDOR) was discovered in the 'Click to Pray' application programming interface (API). This flaw allows any internet user to query a specific API endpoint and access personally identifying information (PII) of account holders, including employees of the Pope's Worldwide Prayer Network. Over 700,000 user accounts are exposed, with email addresses and names leaked in plaintext. The vulnerability requires no technical skill to exploit, only a browser. Attackers could use this data for mass emailing or social engineering schemes, leveraging users' faith. The Pope's Worldwide Prayer Network, which owns the app developed by La Machi, has not yet responded to requests for comment. This incident highlights a common type of vulnerability, broken access control, which remains prevalent across various industries and company sizes, based on information published by Dark Reading.

Source: Dark Reading

You can skip this ad in 5 seconds