Vietnamese crab exporter

Bihar's Magadh University website flaw may expose 2TB student data: Researcher

The website of Bihar's Magadh University may have a major cybersecurity flaw potentially exposing 2TB of student data, including names, marksheets, addresses and Aadhaar numbers. Cybersecurity researcher Mayank Kumar shared details with India Today Tech.

advertisement
2TB of sensitive data from Bihar's Magadh University may be at risk. (Photo was upscaled using AI)

Hot on the heels of the Bank of Baroda data leak, another major cybersecurity loophole has been found, this time allegedly in the Bihar Magadh University website. An independent cybersecurity researcher—Mayank Kumar—claims that the official website of the Magadh University has a flaw putting up to 2TB of confidential data including names, addresses, and Aadhaar numbers of students at risk.

advertisement

Magadh University is affiliated with 39 colleges, along with 19 constituent colleges, and so, the reported vulnerability if it is left unchecked can potentially impact lakhs of students, the researcher claims. “If this data falls into the wrong hands, it could be used for identity theft, financial fraud, forged documents, blackmail, or other cybercrimes affecting thousands of students and staff,” Kumar tells India Today Tech.

Mayank Kumar says that sensitive data of students and staff may be at risk.

The researcher said the said vulnerability—he has spotted—was flagged to India's national cybersecurity agency, CERT-in. Magadh University was also separately informed. Though, he is yet to get any response from both parties, Kumar adds.

advertisement

What is the flaw?

According to Mayank, he discovered a severe security vulnerability called SQL injection in the official Magadh University website. “This allows an attacker to access and even change data stored on the university's servers without proper authorisation,” he explains.

That is, by using SQL codes, an attacker can gain access to the database stored by the website. The attacker can then view, copy, change, or even delete the stored data. In this case, it includes marksheets and academic records, Aadhaar card details, signatures, home addresses and contact information connected to affiliated colleges across the state. Kumar estimates the data to be up 2TB.

If a hacker manages to use this flaw, it may have major consequences, and not be limited to students. Mayank says, “It could have been misused for identity theft, fraud, forged documents, or other crimes affecting a very large number of people, not just students, but their families too.”

Kumar labelled the flaw to be “a basic but very serious mistake” for an institution like Magadh University that manages sensitive personal data.

A few days ago, a similar vulnerability was found in the Bihar Mahadalit Vikas Mission (BMVM) website, which has been fixed.

- Ends
Published By:
Armaan Agarwal
Published On:
Jul 29, 2026 15:57 IST

Hot on the heels of the Bank of Baroda data leak, another major cybersecurity loophole has been found, this time allegedly in the Bihar Magadh University website. An independent cybersecurity researcher—Mayank Kumar—claims that the official website of the Magadh University has a flaw putting up to 2TB of confidential data including names, addresses, and Aadhaar numbers of students at risk.

Magadh University is affiliated with 39 colleges, along with 19 constituent colleges, and so, the reported vulnerability if it is left unchecked can potentially impact lakhs of students, the researcher claims. “If this data falls into the wrong hands, it could be used for identity theft, financial fraud, forged documents, blackmail, or other cybercrimes affecting thousands of students and staff,” Kumar tells India Today Tech.

Mayank Kumar says that sensitive data of students and staff may be at risk.

The researcher said the said vulnerability—he has spotted—was flagged to India's national cybersecurity agency, CERT-in. Magadh University was also separately informed. Though, he is yet to get any response from both parties, Kumar adds.

What is the flaw?

According to Mayank, he discovered a severe security vulnerability called SQL injection in the official Magadh University website. “This allows an attacker to access and even change data stored on the university's servers without proper authorisation,” he explains.

That is, by using SQL codes, an attacker can gain access to the database stored by the website. The attacker can then view, copy, change, or even delete the stored data. In this case, it includes marksheets and academic records, Aadhaar card details, signatures, home addresses and contact information connected to affiliated colleges across the state. Kumar estimates the data to be up 2TB.

If a hacker manages to use this flaw, it may have major consequences, and not be limited to students. Mayank says, “It could have been misused for identity theft, fraud, forged documents, or other crimes affecting a very large number of people, not just students, but their families too.”

Kumar labelled the flaw to be “a basic but very serious mistake” for an institution like Magadh University that manages sensitive personal data.

A few days ago, a similar vulnerability was found in the Bihar Mahadalit Vikas Mission (BMVM) website, which has been fixed.

- Ends
Published By:
Armaan Agarwal
Published On:
Jul 29, 2026 15:57 IST

Hot on the heels of the Bank of Baroda data leak, another major cybersecurity loophole has been found, this time allegedly in the Bihar Magadh University website. An independent cybersecurity researcher—Mayank Kumar—claims that the official website of the Magadh University has a flaw putting up to 2TB of confidential data including names, addresses, and Aadhaar numbers of students at risk.

Magadh University is affiliated with 39 colleges, along with 19 constituent colleges, and so, the reported vulnerability if it is left unchecked can potentially impact lakhs of students, the researcher claims. “If this data falls into the wrong hands, it could be used for identity theft, financial fraud, forged documents, blackmail, or other cybercrimes affecting thousands of students and staff,” Kumar tells India Today Tech.

Mayank Kumar says that sensitive data of students and staff may be at risk.

The researcher said the said vulnerability—he has spotted—was flagged to India's national cybersecurity agency, CERT-in. Magadh University was also separately informed. Though, he is yet to get any response from both parties, Kumar adds.

What is the flaw?

According to Mayank, he discovered a severe security vulnerability called SQL injection in the official Magadh University website. “This allows an attacker to access and even change data stored on the university's servers without proper authorisation,” he explains.

That is, by using SQL codes, an attacker can gain access to the database stored by the website. The attacker can then view, copy, change, or even delete the stored data. In this case, it includes marksheets and academic records, Aadhaar card details, signatures, home addresses and contact information connected to affiliated colleges across the state. Kumar estimates the data to be up 2TB.

If a hacker manages to use this flaw, it may have major consequences, and not be limited to students. Mayank says, “It could have been misused for identity theft, fraud, forged documents, or other crimes affecting a very large number of people, not just students, but their families too.”

Kumar labelled the flaw to be “a basic but very serious mistake” for an institution like Magadh University that manages sensitive personal data.

A few days ago, a similar vulnerability was found in the Bihar Mahadalit Vikas Mission (BMVM) website, which has been fixed.

- Ends
Published By:
Armaan Agarwal
Published On:
Jul 29, 2026 15:57 IST

Read more!
advertisement

Explore More