news.mlab.sh
Back to the feed
vulnerability

Click to pray expose les données de plus de 700 000 fidèles

High
Image: ZATAZ
Summary

A vulnerability in the Click to Pray application, used by the Vatican’s prayer network, has exposed the personal data of over 719,517 users. Researcher BobDaHacker reported the issue six months prior, but no response was received. The flaw, a simple IDOR vulnerability, allows attackers to access user profiles including email addresses, names, countries, birthdates, and account status, creating a significant risk for phishing campaigns targeting a potentially vulnerable user base, particularly older users unfamiliar with digital security risks. The Vatican’s prayer network has not responded to the report.

Read the full article at ZATAZ

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.