Patna: A major security vulnerability in the Bihar Mahadalit Vikas Mission (BMVM) website reportedly exposed sensitive information of millions of citizens, including Aadhaar details, pension records, beneficiary data and government officials’ login credentials. The security flaw was discovered by 21-year-old student Prashant Kumar, who alerted authorities about the potential risk.
The vulnerability reportedly allowed unauthorised users to access the website’s database without logging in. According to Prashant, the flaw could have enabled attackers to view, modify or delete sensitive records stored on the government platform.
The issue was reported to the Indian Computer Emergency Response Team (CERT-In), following which the matter was escalated to the website’s technical team. The vulnerability has reportedly been fixed after being brought to the authorities’ attention.
BMVM website vulnerability exposed critical government data
The Bihar Mahadalit Vikas Mission website is an official platform of the Bihar government used for accessing and managing beneficiary information related to various welfare schemes.
Such government databases often contain large volumes of personal information belonging to citizens who apply for welfare programmes. Due to the nature of the data stored, any security breach could create serious privacy and cybersecurity concerns.
Prashant Kumar told India Today Tech that the database reportedly contained sensitive information, including Aadhaar numbers, phone numbers, PAN card details and banking information linked to schemes requiring account verification.
In cases where beneficiaries provided bank details for receiving government assistance, information such as account numbers and IFSC codes was also reportedly available.
SQL injection flaw allowed possible database access
According to Prashant Kumar, the vulnerability was linked to a SQL injection issue in the website’s “forgot password” page.
SQL injection is a type of cyber vulnerability where attackers can insert malicious database commands into website inputs to access or manipulate stored information. If proper security checks are not implemented, attackers may gain unauthorised access to databases.
Prashant explained that the BMVM website appeared to rely only on client-side security checks rather than implementing necessary protections on the server side.
Client-side checks are performed on a user’s device, which means they can potentially be modified or bypassed. Server-side validation provides an additional layer of protection because it is controlled by the website’s own infrastructure.
According to Prashant, bypassing the client-side checks could allow a person with basic SQL knowledge to interact with the database.
Sensitive records and official credentials reportedly at risk
The security researcher claimed that the database account used by the website had read access to 57 databases hosted on the server.
The exposed information reportedly included multiple categories of sensitive records, such as:
- Aadhaar and PAN details of recruitment applicants
- Driver training applicant information, including addresses and marks
- Pension-related beneficiary data
- Land records
- MGNREGA-related information
- Voter-related datasets
- Livelihood scheme records
The database reportedly also contained login credentials of around 673 government officials, including District Magistrates and Block Development Officers.
If such credentials were misused, attackers could potentially attempt to access administrative sections of the website, creating additional risks for government systems.
Cybersecurity experts have repeatedly warned that government databases require strong access controls, encryption and regular security audits due to the sensitive nature of citizen information they store.
Student researcher reports flaw to authorities
Prashant Kumar discovered the vulnerability while analysing the security of the BMVM website. After identifying the issue, he reported it to CERT-In, the national agency responsible for responding to cybersecurity incidents.
According to reports, CERT-In informed him that the matter had been forwarded to the team responsible for maintaining the website.
The discovery highlights the growing role of independent security researchers and ethical hackers in identifying vulnerabilities before they are exploited by malicious actors.
Many organisations, including government departments, encourage responsible disclosure programmes where researchers can report security weaknesses without publicly exposing sensitive details.
Rising concerns over government data security
The Bihar website vulnerability comes amid increasing concerns over cybersecurity threats targeting government and financial systems in India.
In recent years, several incidents have highlighted the risks associated with storing large amounts of personal information online. Government platforms often manage data related to welfare schemes, identity verification, employment applications and financial assistance programmes.
Earlier, security vulnerabilities were reportedly identified in the Central Board of Secondary Education (CBSE) website by Class 12 students. Such incidents have increased discussions around the need for stronger cybersecurity awareness among institutions.
Recently, concerns were also raised after reports of an alleged Bank of Baroda data leak involving sensitive banking information.
Need for stronger cybersecurity measures
Experts say government websites handling citizen data must follow strict security practices, including regular vulnerability testing, server-side validation, encryption of sensitive information and restricted database access.
Employee credentials should also be protected through stronger authentication systems, including multi-factor authentication wherever possible.
As more public services move online, protecting citizen information has become a critical responsibility for government agencies.
Conclusion
The discovery of the BMVM website vulnerability by a 21-year-old student has highlighted the importance of proactive cybersecurity measures in protecting public data. While the flaw has reportedly been fixed, the incident underlines the need for continuous security audits and stronger safeguards for government platforms handling sensitive citizen information.


