NEW: A bug in a student admissions website exposed the personal information of parents and their children, including their names, dates of birth, home addresses, pictures, and details about their school.
The bug, now fixed, was a sequential IDOR. At least 1.63 million student records were exposed.

Exclusive: Bug in student admissions website exposed children's personal information
Ravenna Hub, which lets parents apply and track the status of their kids' applications across thousands of schools, allowed any logged-in user to access the personally identifiable data associated with any other user, including their children.
techcrunch.com · TechCrunch
Link author:
Zack Whittaker@zackwhittaker@mastodon.social