Vietnamese crab exporter

21-year-old student finds major flaw in Bihar Govt website potentially exposing Aadhaar, pension data

The Bihar Mahadalit Vikas Mission (BMVM) website had a major security flaw that put the data of millions of Indians at risk. This included Aadhaar numbers, pension details, scheme beneficiaries, as well as credentials of government officials. This flaw was spotted by 21-year-old Prashant Kumar, who shared details with India Today Tech.

advertisement
A flaw in a Bihar government website could've exposed data of millions online. (Representational image made with AI)

A Bihar government website had a major security flaw that put the data of millions of Indians at risk. That is, anyone could have exploited this flaw to access sensitive data, including Aadhaar numbers, pension details, ID of government officials, and more. The vulnerability was spotted in the Bihar Mahadalit Vikas Mission (BMVM) website by 21-year-old Prashant Kumar, who shared the details with India Today Tech.

advertisement

The Bihar Mahadalit Vikas Mission (BMVM) website is an official website of the Government of Bihar. It is used to access beneficiary schemes of the state government. As a result, if compromised, it can give access to personal details of residents to any hacker.

Prashant Kumar claimed that the flaw could've potentially exposed data of millions.

To give you some context of how critical such a breach could be, the website included a database of critical information. Prashant Kumar told India Today Tech, “That data includes Aadhaar, phone number, PAN card. And in schemes, where a bank account is required, there is also data of bank account – account number, IFSC codes.”

advertisement

Bihar website flaw

Prashant Kumar explained that the flaw was linked to SQL injection to a forgot password page on the BMVM website. This flaw allowed anyone to access the database, make changes, copy data, or even make deletions without having to log in.

You see, a website usually has two checks when it comes to SQL injections, one on the client side, that is your device, and the other on the host site. But in this case, Prashant said that the check was only made on the client side. He added, “This website is just doing it on the client-side, they are not doing it on the server-side.”

According to Prashant, only client-side checks make a webpage more vulnerable. He explained, “If something is checked in my phone so, we can remove that check, because the phone is with me we can change its complete code we can do anything.”

This meant that anyone could access the database by using SQL codes in this forgot password page, where originally they would have had to fill in their personal details. Prashant said, “We can put the SQL code for anything, to read the database or to change the database or even delete it entirely.”

advertisement

And, Prashant believes that this flaw was so easy to exploit that someone with basic understanding of how SQL works could’ve gained access. “Anyone who has learnt SQL database as a student could access the database with this flaw,” Prashant Kumar explained.

Prashant Kumar reported CERT-in of the vulnerability after spotting it. He was informed that the matter had been escalated to the team behind the website. At the time of writing, the flaw had been fixed.

What data was at risk of being exposed?

According to Prashant, the database account used by the website had read access to 57 databases on its server. The database includes recruitment applicant data containing Aadhaar and PAN details and, in some cases, passwords stored in plaintext. There were also driver-training applicant records with addresses, Aadhaar details and marks.

One could also gain access to login credentials of about 673 government officials, including District Magistrates and Block Development Officers. This could allow anyone to access the admin panel of the website by using these official IDs. The database also included large welfare datasets covering pensions, land records, MGNREGA, voter data and livelihood scheme data.

This is not the first time a student has managed to find major flaws in a government website in India. Earlier this year, Class 12 students found major security vulnerabilities in the CBSE website that sparked outrage. Meanwhile, fears over data leaks have also risen. Recently, it was found that 1TB of sensitive data from Bank of Baroda had been leaked online for free.

- Ends
Published By:
Armaan Agarwal
Published On:
Jul 28, 2026 09:14 IST

A Bihar government website had a major security flaw that put the data of millions of Indians at risk. That is, anyone could have exploited this flaw to access sensitive data, including Aadhaar numbers, pension details, ID of government officials, and more. The vulnerability was spotted in the Bihar Mahadalit Vikas Mission (BMVM) website by 21-year-old Prashant Kumar, who shared the details with India Today Tech.

The Bihar Mahadalit Vikas Mission (BMVM) website is an official website of the Government of Bihar. It is used to access beneficiary schemes of the state government. As a result, if compromised, it can give access to personal details of residents to any hacker.

Prashant Kumar claimed that the flaw could've potentially exposed data of millions.

To give you some context of how critical such a breach could be, the website included a database of critical information. Prashant Kumar told India Today Tech, “That data includes Aadhaar, phone number, PAN card. And in schemes, where a bank account is required, there is also data of bank account – account number, IFSC codes.”

Bihar website flaw

Prashant Kumar explained that the flaw was linked to SQL injection to a forgot password page on the BMVM website. This flaw allowed anyone to access the database, make changes, copy data, or even make deletions without having to log in.

You see, a website usually has two checks when it comes to SQL injections, one on the client side, that is your device, and the other on the host site. But in this case, Prashant said that the check was only made on the client side. He added, “This website is just doing it on the client-side, they are not doing it on the server-side.”

According to Prashant, only client-side checks make a webpage more vulnerable. He explained, “If something is checked in my phone so, we can remove that check, because the phone is with me we can change its complete code we can do anything.”

This meant that anyone could access the database by using SQL codes in this forgot password page, where originally they would have had to fill in their personal details. Prashant said, “We can put the SQL code for anything, to read the database or to change the database or even delete it entirely.”

And, Prashant believes that this flaw was so easy to exploit that someone with basic understanding of how SQL works could’ve gained access. “Anyone who has learnt SQL database as a student could access the database with this flaw,” Prashant Kumar explained.

Prashant Kumar reported CERT-in of the vulnerability after spotting it. He was informed that the matter had been escalated to the team behind the website. At the time of writing, the flaw had been fixed.

What data was at risk of being exposed?

According to Prashant, the database account used by the website had read access to 57 databases on its server. The database includes recruitment applicant data containing Aadhaar and PAN details and, in some cases, passwords stored in plaintext. There were also driver-training applicant records with addresses, Aadhaar details and marks.

One could also gain access to login credentials of about 673 government officials, including District Magistrates and Block Development Officers. This could allow anyone to access the admin panel of the website by using these official IDs. The database also included large welfare datasets covering pensions, land records, MGNREGA, voter data and livelihood scheme data.

This is not the first time a student has managed to find major flaws in a government website in India. Earlier this year, Class 12 students found major security vulnerabilities in the CBSE website that sparked outrage. Meanwhile, fears over data leaks have also risen. Recently, it was found that 1TB of sensitive data from Bank of Baroda had been leaked online for free.

- Ends
Published By:
Armaan Agarwal
Published On:
Jul 28, 2026 09:14 IST

A Bihar government website had a major security flaw that put the data of millions of Indians at risk. That is, anyone could have exploited this flaw to access sensitive data, including Aadhaar numbers, pension details, ID of government officials, and more. The vulnerability was spotted in the Bihar Mahadalit Vikas Mission (BMVM) website by 21-year-old Prashant Kumar, who shared the details with India Today Tech.

The Bihar Mahadalit Vikas Mission (BMVM) website is an official website of the Government of Bihar. It is used to access beneficiary schemes of the state government. As a result, if compromised, it can give access to personal details of residents to any hacker.

Prashant Kumar claimed that the flaw could've potentially exposed data of millions.

To give you some context of how critical such a breach could be, the website included a database of critical information. Prashant Kumar told India Today Tech, “That data includes Aadhaar, phone number, PAN card. And in schemes, where a bank account is required, there is also data of bank account – account number, IFSC codes.”

Bihar website flaw

Prashant Kumar explained that the flaw was linked to SQL injection to a forgot password page on the BMVM website. This flaw allowed anyone to access the database, make changes, copy data, or even make deletions without having to log in.

You see, a website usually has two checks when it comes to SQL injections, one on the client side, that is your device, and the other on the host site. But in this case, Prashant said that the check was only made on the client side. He added, “This website is just doing it on the client-side, they are not doing it on the server-side.”

According to Prashant, only client-side checks make a webpage more vulnerable. He explained, “If something is checked in my phone so, we can remove that check, because the phone is with me we can change its complete code we can do anything.”

This meant that anyone could access the database by using SQL codes in this forgot password page, where originally they would have had to fill in their personal details. Prashant said, “We can put the SQL code for anything, to read the database or to change the database or even delete it entirely.”

And, Prashant believes that this flaw was so easy to exploit that someone with basic understanding of how SQL works could’ve gained access. “Anyone who has learnt SQL database as a student could access the database with this flaw,” Prashant Kumar explained.

Prashant Kumar reported CERT-in of the vulnerability after spotting it. He was informed that the matter had been escalated to the team behind the website. At the time of writing, the flaw had been fixed.

What data was at risk of being exposed?

According to Prashant, the database account used by the website had read access to 57 databases on its server. The database includes recruitment applicant data containing Aadhaar and PAN details and, in some cases, passwords stored in plaintext. There were also driver-training applicant records with addresses, Aadhaar details and marks.

One could also gain access to login credentials of about 673 government officials, including District Magistrates and Block Development Officers. This could allow anyone to access the admin panel of the website by using these official IDs. The database also included large welfare datasets covering pensions, land records, MGNREGA, voter data and livelihood scheme data.

This is not the first time a student has managed to find major flaws in a government website in India. Earlier this year, Class 12 students found major security vulnerabilities in the CBSE website that sparked outrage. Meanwhile, fears over data leaks have also risen. Recently, it was found that 1TB of sensitive data from Bank of Baroda had been leaked online for free.

- Ends
Published By:
Armaan Agarwal
Published On:
Jul 28, 2026 09:14 IST

Read more!
advertisement

Explore More