Bihar's Magadh University website flaw may expose 2TB student data: Researcher
The website of Bihar's Magadh University may have a major cybersecurity flaw potentially exposing 2TB of student data, including names, marksheets, addresses and Aadhaar numbers. Cybersecurity researcher Mayank Kumar shared details with India Today Tech.

Hot on the heels of the Bank of Baroda data leak, another major cybersecurity loophole has been found, this time allegedly in the Bihar Magadh University website. An independent cybersecurity researcher—Mayank Kumar—claims that the official website of the Magadh University has a flaw putting up to 2TB of confidential data including names, addresses, and Aadhaar numbers of students at risk.
Magadh University is affiliated with 39 colleges, along with 19 constituent colleges, and so, the reported vulnerability if it is left unchecked can potentially impact lakhs of students, the researcher claims. “If this data falls into the wrong hands, it could be used for identity theft, financial fraud, forged documents, blackmail, or other cybercrimes affecting thousands of students and staff,” Kumar tells India Today Tech.
The researcher said the said vulnerability—he has spotted—was flagged to India's national cybersecurity agency, CERT-in. Magadh University was also separately informed. Though, he is yet to get any response from both parties, Kumar adds.
What is the flaw?
According to Mayank, he discovered a severe security vulnerability called SQL injection in the official Magadh University website. “This allows an attacker to access and even change data stored on the university's servers without proper authorisation,” he explains.
That is, by using SQL codes, an attacker can gain access to the database stored by the website. The attacker can then view, copy, change, or even delete the stored data. In this case, it includes marksheets and academic records, Aadhaar card details, signatures, home addresses and contact information connected to affiliated colleges across the state. Kumar estimates the data to be up 2TB.
If a hacker manages to use this flaw, it may have major consequences, and not be limited to students. Mayank says, “It could have been misused for identity theft, fraud, forged documents, or other crimes affecting a very large number of people, not just students, but their families too.”
Kumar labelled the flaw to be “a basic but very serious mistake” for an institution like Magadh University that manages sensitive personal data.
A few days ago, a similar vulnerability was found in the Bihar Mahadalit Vikas Mission (BMVM) website, which has been fixed.
Hot on the heels of the Bank of Baroda data leak, another major cybersecurity loophole has been found, this time allegedly in the Bihar Magadh University website. An independent cybersecurity researcher—Mayank Kumar—claims that the official website of the Magadh University has a flaw putting up to 2TB of confidential data including names, addresses, and Aadhaar numbers of students at risk.
Magadh University is affiliated with 39 colleges, along with 19 constituent colleges, and so, the reported vulnerability if it is left unchecked can potentially impact lakhs of students, the researcher claims. “If this data falls into the wrong hands, it could be used for identity theft, financial fraud, forged documents, blackmail, or other cybercrimes affecting thousands of students and staff,” Kumar tells India Today Tech.
The researcher said the said vulnerability—he has spotted—was flagged to India's national cybersecurity agency, CERT-in. Magadh University was also separately informed. Though, he is yet to get any response from both parties, Kumar adds.
What is the flaw?
According to Mayank, he discovered a severe security vulnerability called SQL injection in the official Magadh University website. “This allows an attacker to access and even change data stored on the university's servers without proper authorisation,” he explains.
That is, by using SQL codes, an attacker can gain access to the database stored by the website. The attacker can then view, copy, change, or even delete the stored data. In this case, it includes marksheets and academic records, Aadhaar card details, signatures, home addresses and contact information connected to affiliated colleges across the state. Kumar estimates the data to be up 2TB.
If a hacker manages to use this flaw, it may have major consequences, and not be limited to students. Mayank says, “It could have been misused for identity theft, fraud, forged documents, or other crimes affecting a very large number of people, not just students, but their families too.”
Kumar labelled the flaw to be “a basic but very serious mistake” for an institution like Magadh University that manages sensitive personal data.
A few days ago, a similar vulnerability was found in the Bihar Mahadalit Vikas Mission (BMVM) website, which has been fixed.
Hot on the heels of the Bank of Baroda data leak, another major cybersecurity loophole has been found, this time allegedly in the Bihar Magadh University website. An independent cybersecurity researcher—Mayank Kumar—claims that the official website of the Magadh University has a flaw putting up to 2TB of confidential data including names, addresses, and Aadhaar numbers of students at risk.
Magadh University is affiliated with 39 colleges, along with 19 constituent colleges, and so, the reported vulnerability if it is left unchecked can potentially impact lakhs of students, the researcher claims. “If this data falls into the wrong hands, it could be used for identity theft, financial fraud, forged documents, blackmail, or other cybercrimes affecting thousands of students and staff,” Kumar tells India Today Tech.
The researcher said the said vulnerability—he has spotted—was flagged to India's national cybersecurity agency, CERT-in. Magadh University was also separately informed. Though, he is yet to get any response from both parties, Kumar adds.
What is the flaw?
According to Mayank, he discovered a severe security vulnerability called SQL injection in the official Magadh University website. “This allows an attacker to access and even change data stored on the university's servers without proper authorisation,” he explains.
That is, by using SQL codes, an attacker can gain access to the database stored by the website. The attacker can then view, copy, change, or even delete the stored data. In this case, it includes marksheets and academic records, Aadhaar card details, signatures, home addresses and contact information connected to affiliated colleges across the state. Kumar estimates the data to be up 2TB.
If a hacker manages to use this flaw, it may have major consequences, and not be limited to students. Mayank says, “It could have been misused for identity theft, fraud, forged documents, or other crimes affecting a very large number of people, not just students, but their families too.”
Kumar labelled the flaw to be “a basic but very serious mistake” for an institution like Magadh University that manages sensitive personal data.
A few days ago, a similar vulnerability was found in the Bihar Mahadalit Vikas Mission (BMVM) website, which has been fixed.