VentureEd Solutions fixed a vulnerability in Ravenna Hub, a student admissions and application-tracking platform used across thousands of schools, after it was found to expose sensitive information about children and their families. The issue was an insecure direct object reference (IDOR) that allowed any authenticated user to access other users’ records by modifying sequential student identifiers in the URL, enabling access to data beyond their own account.
Exposed information included children’s names, dates of birth, home addresses, photos, and school details, along with parents’ email addresses and phone numbers and information about siblings. VentureEd’s CEO said the company was able to reproduce the issue and remediated it after being alerted, but the company did not clearly commit to user notification and did not confirm whether it can determine if improper access occurred; it also declined to provide details on third-party security testing or internal cybersecurity oversight.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
After TechCrunch discovered the flaw and alerted VentureEd Solutions, the company said it was able to reproduce the issue and fixed it the same day. VentureEd also said it was investigating the incident but did not commit to notifying affected users or say whether it could determine if any improper access had occurred.
An insecure direct object reference vulnerability in the Ravenna Hub student admissions platform allowed any logged-in user to access other families' student profiles by changing sequential profile or student ID values in the URL. Exposed information included children's names, dates of birth, addresses, photos, school details, sibling information, and parents' contact details.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.