CBSE crisis deepens: Students’ data exposed, say cyber activists. india news
New Delhi: Fresh allegations of massive cyber security lapses, data exposure and administrative failures have deepened the controversy over CBSE’s On Screen Marking (OSM) system, with activists now approaching the National Human Rights Commission (NHRC) for immediate intervention to protect the educational rights of students amid continued disruptions in the board’s post-exam processes.The latest controversy began when independent developers and ethical hackers publicly claimed that sensitive student data, scanned answer sheets and question papers linked to CBSE’s digital assessment infrastructure were exposed online due to serious security vulnerabilities. Android developer Siddharth posted on X: “Almost every single Onmark portal built by Edutech is fundamentally insecure, and CBSE is lying to you about the security of student data. We found default passwords, URL-based RCEs, and raw MD5 hashes. Lakhs of students are in danger.”Separately, 19-year-old software engineer Nisarga Adhikari accused X of leaving storage systems belonging to CBSE openly available online. “The CBSE people have not configured their AWS bucket (a public cloud storage container) properly and now we can paginate and index all their media, which has 2026 answer sheets and question papers,” he said. “Anyone on the Internet can download any scanned booklet,” he claimed.Earlier, the official had claimed that he had breached parts of CBSE’s digital assessment infrastructure and flagged alleged security vulnerabilities associated with the OnMark portal.However, CBSE on Sunday said the vulnerabilities found in the portal operated by its service provider have been “contained”.
