logo

Bug in student admissions website exposed children’s personal information

ID: 3e506dd9-e95f-5ac8-b13b-6285be730911

STIX ID: report--3e506dd9-e95f-5ac8-b13b-6285be730911

Feed Name: TechCrunch Security News

Threat Score
70/100

Date Published: 2026-02-19

Date Updated: 2026-04-23

Author: Zack Whittaker

...
...

A security lapse in Ravenna Hub, an admissions platform handling applications for over a million students, allowed any logged-in user to view other students' profiles by changing sequential student ID numbers (an IDOR vulnerability). The flaw exposed sensitive PII — including children's names, dates of birth, addresses, photos, and parents' contact details — across approximately 1.63 million prior records; VenturEd patched the issue after being notified but has not confirmed user notification or whether any improper access occurred.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.