A computer science student discovered a critical SQL injection vulnerability (CVE-2025-14598, CVSS 9.8) in their college's web portal that affected over 100 educational institutions across India, exposing data of 1M+ students. The vulnerability allowed arbitrary SQL queries and potential OS-level command execution. After the vendor became unresponsive, the researcher coordinated disclosure through CERT/CC, leading to an official CVE assignment and patch deployment. The story emphasizes responsible disclosure practices and how classic vulnerabilities still pose massive risks at scale.

5m read timeFrom infosecwriteups.com
Post cover image
462 Impressions