It has been discovered that the Vatican's prayer app, 'Click to Pray,' has a security flaw that has put more than 700,000 users at risk.

It has been discovered that the Vatican's prayer app, 'Click to Pray,' has a vulnerability that allows attackers to see the names and email addresses of all users. The security researcher who discovered this vulnerability reported it to relevant parties, but there has been no response for over six months.
Click to Pray, Click to Leak: The Pope's Official App Exposes 700,000+ User Emails | bobdahacker

Security flaw in Vatican's 'Click to Pray' app leaves over 700,000 global users exposed — app has been leaking user data for over six months and still does | Tom's Hardware
Click to Pray is an app that 'provides three short prayer times each day, encouraging users to encounter Jesus and pray for the Pope's will.' A security researcher named BobDaHacker has discovered a vulnerability in this app that allows hackers to access user information.
According to BobDaHacker, anyone could access user data simply by entering a user ID at the API endpoint . The information that anyone could obtain from the Click To Pray app's database included first and last names, email addresses, and dates of birth.
Furthermore, it was apparently easy to automatically retrieve the entire user list. According to BobDaHacker, the user IDs assigned to new accounts are sequential, and there are no rate limits on the API, so all the information could be collected by sending just one GET request for each user. In addition, the value 'validation_hash,' which is used to verify the validity of account registration, was stored in plain text, meaning that anyone with access to the API could authenticate an account simply by opening their inbox. Moreover, the emails themselves had security vulnerabilities, making even legitimate emails look like phishing emails.

BobDaHacker reported the vulnerability to relevant parties via email immediately after discovering it, but received no response, and no improvements were seen even after six months. Only after the issue was published in an article was the security issue in the app finally fixed. However, the app developer never offered any apologies or thanks to BobDaHacker.
It is estimated that there are approximately 720,000 accounts on Click To Pray. BobDaHacker pointed out that 'many of the users of this app are likely to be elderly people who are not tech-savvy, making it a goldmine for malicious scammers to obtain a large number of email addresses.'
It should be noted that Click To Pray also had a vulnerability exposed back in 2019, when it was first released, that allowed users to view email addresses and other personal information.
Smart rosary app that allows you to pray anytime was found to be incredibly easy to hack - GIGAZINE

Related Posts:






