gaming
Vatican's Click To Pray app exposed 700,000+ user emails via insecure API
Pope Francis promoted the Click To Pray app in 2019. A flaw in its API let anyone retrieve user records by incrementing numeric IDs, exposing names, emails and other personal details. White-hat researcher BobDaHacker publicly disclosed the issue on July 24 after earlier inquiries went unanswered. The vulnerability has since been fixed.
- 700,000+ user emails and personal data exposed
- Predictable numeric user IDs allowed unauthenticated access
- Disclosed publicly by white‑hat researcher after unanswered inquiries
- Issue has been fixed (server indicated use of Express/Node.js)