21-Year-Old Student Discovers Critical Security Flaw in Bihar Government Website, Aadhaar and Pension Data Potentially at Risk

21-Year-Old Student Discovers Critical Security Flaw in Bihar Government Website, Aadhaar and Pension Data Potentially at Risk

A 21-year-old cybersecurity researcher, Prashant Kumar, has reported a critical security vulnerability in the Bihar Mahadalit Vikas Mission (BMVM) website that could have exposed sensitive personal and administrative data.

According to the researcher, the flaw had the potential to provide unauthorised access to multiple databases associated with the government portal, which is used to manage beneficiary schemes in Bihar.

The vulnerability has reportedly been fixed after being disclosed to the Indian Computer Emergency Response Team (CERT-In).


What Was the Security Flaw?

According to Prashant Kumar, the issue involved an SQL injection vulnerability in the website's Forgot Password page.

SQL injection is a common cybersecurity vulnerability that can occur when user input is not properly validated on the server. If left unaddressed, it may allow an attacker to manipulate database queries and potentially access or modify stored information.

The researcher alleged that the BMVM portal relied primarily on client-side validation rather than validating requests on the server, making it possible to bypass restrictions.

These findings are based on the researcher's account and have not been independently verified by All India Story.


What Data Could Have Been Accessed?

According to Prashant Kumar, the vulnerable database account reportedly had access to 57 databases hosted on the server.

The data that could potentially have been exposed included:

  • Aadhaar numbers.
  • PAN details.
  • Mobile numbers.
  • Bank account numbers.
  • IFSC codes.
  • Pension records.
  • Welfare scheme beneficiary information.
  • Driver training applicant records.
  • Recruitment applicant information.
  • Land records.
  • MGNREGA-related data.
  • Voter-related datasets.

The researcher also alleged that some records contained passwords stored in plaintext, although this claim has not been independently verified.


Government Officials' Credentials Also Reportedly Accessible

Prashant Kumar further claimed that the affected databases included login credentials linked to approximately 673 government officials, including District Magistrates and Block Development Officers.

According to the researcher, these credentials could potentially have been used to access administrative functions of the portal if exploited.

There has been no public confirmation from Bihar authorities regarding whether any official accounts were compromised.


Vulnerability Reported to CERT-In

Rather than publicly disclosing the flaw immediately, the researcher said he reported it to CERT-In, India's national cybersecurity incident response agency.

According to him, CERT-In acknowledged the report and escalated it to the team responsible for maintaining the website.

By the time the report was published, the vulnerability had reportedly been fixed.

At present, there is no evidence indicating that the vulnerability was exploited by malicious actors before it was remediated.


What Is SQL Injection?

SQL injection is a well-known web security vulnerability that allows attackers to interfere with database queries if an application improperly handles user input.

If adequate server-side protections are not in place, attackers may be able to:

  • Read sensitive information.
  • Modify database records.
  • Delete stored data.
  • Gain unauthorised administrative access.

Cybersecurity experts generally recommend implementing server-side input validation, parameterised queries and regular security testing to mitigate such risks.


Why This Matters

Government portals often store large volumes of sensitive citizen information, making them attractive targets for cyberattacks. While the reported vulnerability has since been fixed, the incident underscores the importance of regular security audits, responsible vulnerability disclosure and prompt remediation. It also highlights the valuable role that independent security researchers can play in identifying weaknesses before they are exploited.


Frequently Asked Questions (FAQs)

What vulnerability was discovered in the Bihar government website?

A cybersecurity researcher reported an SQL injection vulnerability in the Bihar Mahadalit Vikas Mission (BMVM) website's Forgot Password page.

Who discovered the security flaw?

The vulnerability was reported by 21-year-old cybersecurity researcher Prashant Kumar.

Was citizens' data leaked?

The researcher stated that the vulnerability could have allowed access to sensitive information. However, there is no confirmed evidence that the data was accessed or misused before the issue was fixed.

What information was potentially at risk?

According to the researcher, the databases included Aadhaar numbers, PAN details, bank account information, pension records, welfare scheme data and government official credentials.

Has the issue been fixed?

Yes. According to the report, the vulnerability was fixed after it was reported to CERT-In and escalated to the website administrators.

Prev Article
Anthropic CEO Dario Amodei Says He Doesn't Oppose Open-Weight AI Models, Raises Concerns Over China's AI Capabilities

Related to this topic: