Click to pray expose les données de plus de 700 000 fidèles
A vulnerability in the Click to Pray application, used by the Vatican’s prayer network, has exposed the personal data of over 719,517 users. Researcher BobDaHacker reported the issue six months prior, but no response was received. The flaw, a simple IDOR vulnerability, allows attackers to access user profiles including email addresses, names, countries, birthdates, and account status, creating a significant risk for phishing campaigns targeting a potentially vulnerable user base, particularly older users unfamiliar with digital security risks. The Vatican’s prayer network has not responded to the report.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
