Exposing Critical Vulnerabilities in CBSE's On-Screen Marking Portal
dsr12
46 points
15 comments
May 26, 2026
Related Discussions
Found 5 related stories in 98.0ms across 8,541 title embeddings via pgvector HNSW
- Hackers deface school login pages after claiming another Instructure hack Veiled · 27 pts · May 07, 2026 · 51% similar
- Canvas Breach Disrupts Schools and Colleges Nationwide lschueller · 14 pts · May 08, 2026 · 48% similar
- Google published exploit code for an unfixed Chromium bug logickkk1 · 28 pts · May 20, 2026 · 48% similar
- GitHub RCE Vulnerability: CVE-2026-3854 Breakdown bo0tzz · 298 pts · April 28, 2026 · 47% similar
- N-Day-Bench – Can LLMs find real vulnerabilities in real codebases? mufeedvh · 54 pts · April 13, 2026 · 47% similar
Discussion Highlights (7 comments)
arnavpraneet
To note, this is the largest board of education in India, the most populous country in the world - some 29,000 schools are affiliated to it and millions of students enrolled in a curriculum designed and controlled by the CBSE
varun_ch
This is unbelievable!! At a certain point surely doing things the right way would be easier or more clearly correct? Like, if you were implementing this you’d obviously know that it’s insecure right??
yummybrainz
It's getting real hard to apply Hanlon's razor ("assume ignorance before malice") when it comes to egregious incompetence like this. I wonder if this particular backdoor (front door?) has been used before; perhaps there are black-hat services that sell grade upgrades.
random_ind_dude
India's education sector is a real shit-show. The rot starts at the bottom: students that resort to cheating, the endless question paper leaks of national level examinations, and curricula that are stuck in the past. All these lead to the problem that affects the country's economic and social development: a lack of foundational research in frontier science and technology, where the country is always a follower and never a leader. Maybe these things are to be expected, given that even the Prime Minister's academic credentials are suspected to be bogus.
albert_e
Denials already issued Counter claims too https://x.com/ni5arga/status/2059280940044800050
triceratops
Big oof. A master password shipped in client-side JS. A fake OTP authentication process - "the server sends the OTP back...and the [client code] compares what you typed against that value locally before letting you through" And it gets worse after that.
ni5arga
Author here, thanks for posting about it :)