Stanford Vulnerability Allowed Students to View Other Students

Stanford Vulnerability Allowed Students to View Other Students' Data

Between Jan. 28 and 29, the student briefly accessed the records of 81 students while trying to assess the scope of the vulnerability. The documents were not searchable by name, but were instead accessible by changing a numeric ID in a URL.

The Stanford Daily has reported that a now-fixed security vulnerability allowed Stanford students to view the applications and high school transcripts if they first requested to view their own admission documents under the Family Educational Rights and Privacy Act (FERPA).

The vulnerability was discovered by a student who recently submitted a FERPA request for their own documents in a third-party content management system called NolijWeb.

Between Jan. 28 and 29, the student briefly accessed the records of 81 students while trying to assess the scope of the vulnerability. The documents were not searchable by name, but were instead accessible by changing a numeric ID in a URL.

When a student views one of their files, the URLs and files are linked through numeric IDs. While the vulnerability didn’t allow students to search documents by name or other identifying information, they could change file ID numbers in URLs to access arbitrary students’ files.

“It wasn’t anything sophisticated,” the student said of their methods. The student said anyone with experience in web development could have easily exploited the vulnerability. “You change the ID slightly and it just gives you someone else’s records.”

Accessible documents contained sensitive personal data, potentially including Social Security numbers, ethnicity, home address, citizenship status, criminal status, standardized test scores, personal essays and whether that student applied for financial aid.

According to university spokesperson Brad Hayward, Stanford has not identified other “instances of unauthorized viewing” but is still reviewing the situation. The university will notify the students whose privacy was compromised because of the security flaw.

“We regret this vulnerability in our system and apologize to those whose records were inappropriately viewed,” Hayward wrote in an email to The Daily. “We have worked to remedy the situation as quickly as possible and will continue working to better protect our systems and data.”

Stanford has notified Nolij’s parent company Hyland Software. It’s not clear how many schools using NolijWeb could be subject to the vulnerability.

About the Author

Jessica Davis is the Associate Content Editor for 1105 Media.

Featured

  • AI in Security: Advancing Campus Safety and Considerations for Implementing

    Artificial intelligence (AI) continues to capture attention across every sector, and the physical security industry is no exception. Once seen as experimental, AI-enabled analytics now underpin how organizations monitor environments, detect threats, and make decisions. What was once futuristic is now a practical necessity for safety professionals managing growing volumes of data, tighter resources, and increasing expectations for faster, more accurate responses. Read Now

  • How Cloud Security Solutions Are Transforming Campus Safety

    Campus administrators today face a challenging mandate: deliver stronger security across their facilities while working within tighter budget constraints. From school districts focused on student safety to hospitals protecting patients and staff, the question remains the same: how do you build security infrastructure that evolves with your needs without requiring massive capital investments? Read Now

  • 77% of Americans Support Gun Detection Technology in Schools, Workplaces, and Houses of Worship

    More than three-quarters of Americans (77.4%) believe gun detection technology should be deployed in schools, workplaces, and other public spaces, according to new survey data released recently. The national survey shows strong support for incorporating camera-based gun detection into existing video surveillance systems. Read Now

  • Eagle Eye Networks Launches AI Camera Gun Detection

    Eagle Eye Networks, a provider of cloud video surveillance, recently introduced Eagle Eye Gun Detection, a new layer of protection for schools and businesses that works with existing security cameras and infrastructure. Eagle Eye Networks is the first to build gun detection into its platform. Read Now