This post was originally published on this site.
A popular prayer app connected to the Vatican, “Click to Pray,” has been leaving user information exposed for months, the most recent in a years-long string of vulnerabilities and hacks for Vatican-related websites.
St. Peter’s Basilica. public domain.The app, which is available on both iOS and Android, suffers from an insecure direct object reference (IDOR) vulnerability, cybersecurity news site Dark Reading reported Friday.
As a result, names and email addresses for more than 700,000 users are easily available to any web user, the site said.
The app, which is used by hundreds of thousands of people around the world, is run by the Pope’s Worldwide Prayer Network, which is a pontifical society entrusted to the Society of Jesus, tasked with “supporting the Holy Father’s evangelizing mission through prayer for a mission of compassion for the world.” It offers daily prayer prompts and opportunities to share prayer intentions with other users.
The site reported that the vulnerability was first noted in January by a hacker who goes by “BobDaHacker” on his blog. BobDaHacker and Dark Reading both reported reaching out to officials at the app and the group that runs it,
Read more...