Bug in student admissions website exposed children’s personal information

Bug in student admissions website exposed children’s personal information

A significant security flaw on the student admissions platform Ravenna Hub has been addressed, which previously allowed unauthorized access to sensitive personal information of children. This website, utilized by families to enroll their children in various schools, was inadvertently permitting any logged-in user to view the identifiable data of others, including their children. The compromised information encompassed names, birth dates, addresses, photographs, and school details of the students. Additionally, the site exposed parents' email addresses and phone numbers, along with information about siblings. Managed by Florida-based VentureEd Solutions, Ravenna Hub serves over a million students and processes hundreds of thousands of applications annually. TechCrunch discovered the vulnerability and promptly informed VentureEd, which managed to rectify the issue on the same day. However, TechCrunch chose to delay the report until the fix was confirmed. Nick Laird, the CEO of VentureEd Solutions, acknowledged in an email that the company successfully replicated the issue and resolved the vulnerability. He mentioned that an investigation is underway but did not confirm if users would be notified about the security breach or if there was a means to check for any unauthorized access to data. The vulnerability is categorized as an insecure direct object reference (IDOR), a prevalent security flaw that enables users to access data without adequate security measures in place. Essentially, this flaw allowed any logged-in user to view another student's information by simply altering the unique identifier associated with a student's profile in their browser's address bar. Given that student numbers are sequential, it was easy for users to access the data of other students by adjusting the profile number. Upon creating a new account for testing, TechCrunch identified that the URL contained a seven-digit number, indicating that over 1.63 million records were potentially accessible to any user. This incident marks yet another troubling security breach involving elementary security oversights that jeopardize the personal data of children. Earlier this year, the online mentoring platform UStrive also faced scrutiny for exposing the personal information of many young users.

Sources : TechCrunch

Published On : Feb 19, 2026, 15:30

AI
Apple Revamps Siri with Cutting-Edge AI Features After Delays

In a significant leap forward, Apple has officially launched an upgraded version of Siri, marking a pivotal moment in it...

Business Insider | Jun 08, 2026, 17:50
Apple Revamps Siri with Cutting-Edge AI Features After Delays
Computing
Apple Unveils Major Upgrades at WWDC 2026: A New Era for Siri and iOS

This morning, Apple launched its highly anticipated WWDC 2026 event at Apple Park, kicking off a week packed with exciti...

TechCrunch | Jun 08, 2026, 18:00
Apple Unveils Major Upgrades at WWDC 2026: A New Era for Siri and iOS
Cybersecurity
Microsoft Faces Second Credential Theft Incident Amid Open Source Package Breaches

In a troubling development for Microsoft, several open-source packages were found compromised late last week, harboring ...

Ars Technica | Jun 08, 2026, 18:40
Microsoft Faces Second Credential Theft Incident Amid Open Source Package Breaches
AI
Apple Unveils Revamped Siri AI: A New Era for Voice Assistants

Apple has taken a bold step in transforming its voice assistant, unveiling the newly enhanced Siri AI. This iteration me...

Business Today | Jun 08, 2026, 18:00
Apple Unveils Revamped Siri AI: A New Era for Voice Assistants
Science
Transforming Waste into Green Solutions: The Innovative Use of Polystyrene in Carbon Capture

The consequences of fossil fuel consumption have significantly impacted our atmosphere, filling it with carbon dioxide (...

Ars Technica | Jun 08, 2026, 18:50
Transforming Waste into Green Solutions: The Innovative Use of Polystyrene in Carbon Capture
View All News