Pope’s official prayer app commits cardinal sin, leaks 700K+ users' info

The official Click To Pray app, endorsed by the Pope, has left the personal information of over 700,000 users exposed due to an IDOR vulnerability. This security flaw allows unauthorized access to sensitive account data, creating significant risks for potential phishing attacks.

Edward Kiledjian @ekiledjian