Vatican’s Click to Pray App Exposes 700,000 Users Through Unauthenticated API Flaw
ID: 2de2e42c-4af7-55d6-9fc6-bdb2e9e1fe1a
STIX ID: report--2de2e42c-4af7-55d6-9fc6-bdb2e9e1fe1a
Feed Name: cybersecurityNews.com
Threat Score
## Executive summary An IDOR vulnerability in the Click to Pray application's unauthenticated API exposed personal records for roughly 700,000+ users (names, emails, passwords, country and roles), enabling bulk harvesting and increasing risk of targeted phishing and impersonation; the report describes discovery, testing, and mitigation recommendations and includes the ClicktoPray domain as an IoC.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
