Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Nvidia ramps up early-stage commitment to India’s AI startup ecosystem

Chrome adds new productivity features as browser wars heat up

Reddit testing new AI search feature for shopping

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » A bug in the student admissions website leaks children’s personal information
Startups

A bug in the student admissions website leaks children’s personal information

userBy userFebruary 19, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

A student admissions website that families use to enroll their children in schools has fixed a security flaw that exposed personal information.

Ravenna Hub, a website where parents can apply and track the status of their children’s applications at thousands of schools, allowed logged-in users to access personally identifiable data associated with other users, including their children.

The leaked data includes children’s names, dates of birth, addresses, photos, and school details. Parents’ email addresses and phone numbers, as well as information about the child’s siblings, were also leaked.

Florida-based VenturEd Solutions, which developed and maintains Ravenna Hub, says on the Ravenna Hub website that the company serves more than 1 million students and processes hundreds of thousands of applications annually.

TechCrunch first learned of the vulnerability on Wednesday and alerted the company shortly after. VenturEd fixed the bug on the same day, but TechCrunch withheld this report until it could confirm that the bug had been fixed.

Nick Laird, CEO of VenturEd Solutions, told TechCrunch in an email that the company was able to reproduce the issue and has addressed the vulnerability.

Laird said the company is investigating the incident, but wouldn’t commit to notifying users about the security lapse, and wouldn’t say in response to TechCrunch’s questions whether the company had the ability to confirm whether there had been unauthorized access to other users’ data. We also asked whether security checks on the Ravenna Hub were performed by a third party, and if so, by whom. Mr. Laird did not specify or declined further comment.

It is unclear who, if anyone, is overseeing cybersecurity for VenturEd and Ravenna Hub.

This vulnerability, known as Insecure Direct Object Reference (IDOR), is a common security flaw that allows users to access stored information due to weak or non-existent security controls on the servers involved.

In effect, this bug allows a logged in user to access another student’s data, including personal information, by using the web browser’s address bar to change the unique number associated with the student’s profile.

For Ravenna Hub, student numbers are consecutive. This meant that any user could potentially access another student’s data by changing one or more digits in their profile number.

When TechCrunch created a new account using test data, we found that the web address contained seven digits. So, before our record, there were just over 1.63 million records available to other users.

This is the latest security breach involving a simple security flaw that affects children’s personal information. In January, the online mentoring site UStrive exposed the personal information of its users, many of whom were still in school.


Source link

#Aceleradoras #CapitalRiesgo #EcosistemaStartup #Emprendimiento #InnovaciónEmpresarial #Startups
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleReload wants to provide shared memory to AI agents
Next Article Zuckerberg accused in court of harming teens on social media
user
  • Website

Related Posts

Nvidia ramps up early-stage commitment to India’s AI startup ecosystem

February 20, 2026

Chrome adds new productivity features as browser wars heat up

February 19, 2026

Reddit testing new AI search feature for shopping

February 19, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Nvidia ramps up early-stage commitment to India’s AI startup ecosystem

Chrome adds new productivity features as browser wars heat up

Reddit testing new AI search feature for shopping

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.