Vatican's Official 'Click To Pray' App Has Leaked 700,000 Users' Data For Six Months Despite Warnings
The Vatican's official prayer app has been quietly exposing the personal data of more than 700,000 users worldwide for at least six months, according to a security researcher who says repeated attempts to warn the app's operators went unanswered.
A widely used app with a basic security flaw
"Click to Pray" is the official prayer app of the Pope's Worldwide Prayer Network, offering daily prayers and papal content to users through iOS, Android and a web browser. According to the app's own website, it is used in nearly every country in the world. In January, a security researcher who goes by the handle "BobDaHacker" discovered a flaw known as an insecure direct object reference, or IDOR, in the app's underlying code at clicktopray.org.
The vulnerability allowed any internet user, without any special technical skill, to query a single exposed application programming interface endpoint and retrieve basic personal information belonging to every account holder on the platform, as well as staff accounts belonging to employees of the Pope's Worldwide Prayer Network itself. Cybersecurity outlet Dark Reading independently tested and confirmed the vulnerability remained live as of its reporting.
When users sign up for Click to Pray, they provide a first and last name, an email address, a password and an optional country field. Behind the scenes, each new account is assigned a sequential numerical user ID. Because the app's API endpoint failed to verify whether a request was authorized before returning data, anyone who supplied a valid user ID, in sequence, could retrieve that account's name, email........
