India’s CBSE Uses ChatGPT-Generated Image After Researcher Details Marks-Editing Vulnerabilities in 2 Million-Student Exam System
India’s CBSE, a national school board, faced scrutiny after 19-year-old researcher Nisarga Adhikary said vulnerabilities in its On-Screen Marking portal allowed access to internal systems and the ability to view or change student marks in an examination process affecting more than 2 million students a year. Critics said CBSE later used a ChatGPT-generated image to try to show the system was secure.
Adhikary said he accessed the system in February and reported the flaws to CERT-In. In a detailed write-up, he described a leaked master password, a workaround for client-side OTP validation, tokenless access to the internal application, the ability to change any password without the old one and an IDOR vulnerability that he said allowed a user to act as any account and edit marks. CBSE later took the portal offline; critics also said the board disputed the breach and said no production data was on the affected servers, a claim they said was later contradicted.
From the sources (6 posts)
@deedydasA 19-year old broke into India's largest high school examination system of 2M+ students a year, the CBSE, and was able to view and CHANGE any students' marks. He responsibly wrote to the team 3 months ago, and it took them 3 days to fix on
@deedydasSource: Tweet:
@ni5argaThis is really really bad, found another severe vulnerability in CBSE's OSM portal. Just sent another report to CERT-In.
@deedydas@cbseindia29 @EduMinOfIndia @dpradhanbjp @sanjayjavin @airnewsalerts @AkashvaniAIR @DDNewslive @PIB_India @PTI_News @PIB_Edu This is painfully embarrassing. You just asked ChatGPT to “generate an image to show we’re secure?” Do you think e
@deedydasThis is painfully embarrassing. The national board of education in India just generated an image on ChatGPT to “prove” that they’re secure after a 19yo showed you can edit marks of 2M test takers on their platform. That is after trying to
@deedydas@indianfrontier Maybe this is not abundantly obvious. Generating an AI image shows you lack the respect for criticism or, more likely, are so incompetent that you’re unwilling to even put in a modicum of effort to address the issue and ins