this post was submitted on 25 Jul 2026
558 points (98.8% liked)

Technology

87417 readers
3868 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] Zarobi@aussie.zone 63 points 3 weeks ago* (last edited 3 weeks ago) (17 children)

the API endpoint GET [redacted] will return user data for any account - not just your own account - so long as you supply a valid, five-digit user ID. It doesn’t perform any authorization check or ownership validation. “Just increment the number and get someone else's data,” she wrote.

This data includes users’ email addresses, first and last names, country, dates of birth, and whether the account has been deleted, and the API exposes all 719,517 accounts on the prayer site. “With sequential user IDs and no rate limiting, an attacker could enumerate every single account on the platform,” the hacker explained. “One GET request per user. for i in range(1, 719518): scrape(). That's it. That's the exploit.”

My God, that's horrific. Plus it doesn't even delete your data if you delete your account, it's still vulnerable.

[–] Appoxo@lemmy.dbzer0.com 16 points 3 weeks ago* (last edited 3 weeks ago) (4 children)

I wonder of the vatican is part of the gdpr...
Would be funny to read about the church getting sued for that.

[–] Zarobi@aussie.zone 4 points 3 weeks ago (3 children)

I don't know much about GDPR… is it illegal to have badly written software like this? Technically the user is bypassing normal usage and "hacking" the API

[–] xiii@lemmy.world 7 points 3 weeks ago

It is illegal to keep deleted profiles

load more comments (2 replies)
load more comments (2 replies)
load more comments (14 replies)