Application programming interface (API) bugs in the Edulog Parent Portal platform allowed bad actors to access names and geolocation data of six million K-12 riders, according to researchers.Edulog Parent Portal, a service that provides real-time school bus tracking for parents of grade-school students, has since fixed the vulnerability.According to Edulog's parent company Education Logistics, "Every day, over 6 million students are transported on over 85,000 buses routed by Edulog software."The flaw allowed anyone who created a free Edulog account to bypass a school registration safeguards and gain “unfettered access” to any information available through the service's Parent Portal API, Tenable researchers reported Wednesday. This information included students’ names, GPS locations of the buses they were assigned to and parent contact information. The flaws also allowed access to platform configuration details "such as usernames and encrypted passwords for third-party integrations – for individual school districts," Tenable wrote.Tenable reported the exposed data to Edulog on Sept. 13, 2023. Edulog said all the reported issues were resolved as of Nov. 30, 2023. There is no indication the exposed data was misused prior to the fix.
API security, Application security, Cloud Security
K-12 student geolocation data, names exposed via API flaws: 6M kids impacted

An In-Depth Guide to Application Security
Get essential knowledge and practical strategies to fortify your applications.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds