Security researchers identified critical vulnerabilities in educational institution web applications, enabling unauthorized access to sensitive student data. In one case, a penetration tester discovered a SQL injection flaw in an educational website's receipt download endpoint, which allowed the attacker to enumerate university numbers, exploit the vulnerability using sqlmap, and ultimately dump the database containing personally identifiable information (PII) of students. Attempts to escalate the attack to an OS shell were unsuccessful due to insufficient permissions, but the exposure of student records highlights the severity of the flaw.
Another incident involved a manual penetration test against a major university's web infrastructure, where the tester bypassed automated tools and used manual techniques to identify and exploit weaknesses in a subdomain's registration functionality. The attacker was able to register as a non-member, receive verification codes, and gain deeper access, demonstrating the risks posed by insufficient input validation and weak authentication mechanisms in academic environments. These incidents underscore the ongoing threat of SQL injection and the need for robust security controls in educational sector web applications.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A separate write-up reported that an SQL injection issue led to a dump of student personally identifiable information. The available metadata does not specify the affected institution, discovery date, or any response actions.
A write-up describing the compromise of IIT Delhi was published, indicating the underlying security incident or testing activity had already occurred. No specific attack date, impact details, or remediation timeline are provided in the reference metadata.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.