A Ravenna Hub data breach exposed the personal data of minors and their families. The student admissions platform flaw allowed any authenticated user to access sensitive data belonging to other users. The vulnerability was reported to the company and remediated within the same day.Â
The vulnerability, reported by TechCrunch, has been classified as an Insecure Direct Object Reference (IDOR) security flaw, as inadequate authorization controls permitted access to unauthorized data resources.
In this instance, an authenticated parent could manipulate the seven-digit sequential identifier in their browser's URL to access other students' profiles. The compromised data encompassed:
The platform, developed by VenturEd Solutions, is utilized by thousands of educational institutions and contains over 1.6 million accessible records.
Platforms such as Ravenna Hub process substantial volumes of highly sensitive data, rendering them high-value targets for threat actors. While the company confirmed remediation of the vulnerability, it provided no statement regarding user notification protocols or forensic analysis to determine potential malicious exploitation.Â
A Spanish Ministry data breach was claimed by a threat actor operating under the alias "GordonFreeman," who alleged the exploitation of an IDOR vulnerability.