the API endpoint GET
https://api/[.]clicktopray.org/user/users/%7Bid%7Dwill return user data for any account - not just your own account - so long as you supply a valid, five-digit user ID. It doesn’t perform any authorization check or ownership validation. “Just increment the number and get someone else’s data,” she wrote.This data includes users’ email addresses, first and last names, country, dates of birth, and whether the account has been deleted, and the API exposes all 719,517 accounts on the prayer site. “With sequential user IDs and no rate limiting, an attacker could enumerate every single account on the platform,” the hacker explained. “One GET request per user. for i in range(1, 719518): scrape(). That’s it. That’s the exploit.”
My God, that’s horrific. Plus it doesn’t even delete your data if you delete your account, it’s still vulnerable.
5 digit user ids, yet over 700k users? Im sure they must have gone up to 6 digits
Unless by “digit” they mean any alphanumeric.
You’ve got a lot of options if you go to a 5 characters with letters.
Which they’d kind of have to with 700k users if it’s 5 characters.
If it’s case insensitive, you’ve got 60,000,000+ combinations, and if case sensitive then 916,000,000+ combinations.
They probably meant 6 digit and it was a typo. The rest of the article references 6 digits. If it’s just an integer (highly likely) it would go up to 10 digits or roughly 2 billion max users. My old coworkers and I used to joke that hitting
INTEGER.MAX_VALUEfor your customer ID is a good problem to have
Was this vibe coded?
That would be rather ironic.
I’ve seen so many stories about leaks that I skip most of them. I’m glad I didn’t skip this one.
Turns out the biggest miracle wasn’t multiplying loaves, it was making authentication disappear. An IDOR this basic on an app handling personal data is embarrassing. 🙈
Why does it need any personal details at all??
So they know what sins I’ve committed.
They don’t follow my mastodon feed. It’s much easier that way.
Historically? Abuse.
I’m sure they say it’s for security : blocking bots, etc and getting their newsletter or some shit.
So that jesus can torture the bad persons.
For sharing between users, as I understand it.
Username, password is all they need for that. Idiots.
“We are gathered here today because your thoughts and prayers did not secure our app”
The Catholic Church is known for a lot of things. Keeping up with the times (or cyber security) isn’t one of them.
Cyber security isn’t in the bible. Time for an update.
Cyprus 1:1
…. Copy pasta of NIST security standards circa May 2026 …
Nothing could go wrong with this.
Vatican Programmer: Oh, mighty Lord, sitting in the Sky, show me the way to this bug I seek and eliminate ineffectiveness. Amen.
Vatican Programmer: Contractor in India
Still better than vibe coding
The OG vibecoders
So uh… what does a prayer app even do?
Press F to pray respects
It leaks personal data.
It connects users across the globe to pray for the Holy Father’s intentions, and as of July 2026, it has 719,517 registered accounts
The only two screenshots they have on GPlay feature prayer scheduling and sharing your prayer.
Damn, with that many people praying these prayers are about to get real effective. I’m surprised we haven’t heard of their effects and effectiveness yet.
I’d like to see the media mix modeling data to really assess the ROP of these prayers. Cross check that against miracle count and we’ll really be cooking.
See, humans are smart. Praying and blessing things yourself? By hand, so to speak? Boooo! Pedestrian! Ain’t nobody got time fo dat!
the Tibetans believe the prayers and mantras will be blown by the wind to spread the good will and compassion into all pervading space. Therefore, prayer flags are thought to bring benefit to all.
By hanging flags in high places the Lung ta will carry the blessings depicted on the flags to all beings. As wind passes over the surface of the flags, which are sensitive to the slightest movement of the wind, the air is purified and sanctified by the mantras.
I choose to believe that the prayer app is just a hip, new and with it innovation in prayer spreading.

It still works lmao
No email and some other stuff though… maybe they just removed that from the endpoint?
lmao did they vibe patch it or smth
If sinners go to hell, do you even have to do due diligence? Let us pray for the vulnerability to disappear.
Misread it as
Pope’s official prayer app, “Cardinal Sin”…
That’s the official Catholic hook up app. It’s different.
Actually….
I thought that was Roblox?
a pope app? perfect for indulgence micro transactions
I think they patched that one a while ago
Is JD Vance in here? He’s supposed to be Catholic right?
Alcoholic, not Catholic!
To borrow a tenet from another abrahamic religion, trust in God, but tie up your camel.
deleted by creator














