Security Flaws in My College's ERP System
As a B.Tech AIML student at St. Andrews Institute of Technology & Management (SAITM), I discovered severe vulnerabilities in our ERP system built by Sonet Microsystems Pvt Ltd. These flaws exposed sensitive student data and could have allowed admin account takeovers.
Despite multiple reports sent to both SAITM and Sonet, responses were either delayed or non-existent, and critical endpoints remain vulnerable as of May 2, 2025.
Key findings: Unauthenticated student data exposure. APIs revealed personal info, names, DOBs, enrollment numbers, and academic scores without requiring login. Just tweak a URL and you're in.
Broken admin OTP flow. OTP verification could be accessed without context or user ID, making brute-force attacks plausible.
Unpatched vulnerabilities. Even after raising concerns in April, one endpoint is still leaking student records publicly.
Disclosure timeline: reported to the college's cyber security analyst and Sonet's enquiry email with detailed write-ups, screenshots, and suggested fixes. Minimal action was taken. This post exists because responsible disclosure only works when someone is responsible on the other end.