{"id":12826,"date":"2026-05-26T22:13:20","date_gmt":"2026-05-26T16:43:20","guid":{"rendered":"https:\/\/banitoday.com\/cbse-faces-fresh-scrutiny-after-teen-researcher-alleges-critical-flaws-in-osm-portal-claims-class-12-marks-could-be-altered\/"},"modified":"2026-05-26T22:13:20","modified_gmt":"2026-05-26T16:43:20","slug":"cbse-faces-fresh-scrutiny-after-teen-researcher-alleges-critical-flaws-in-osm-portal-claims-class-12-marks-could-be-altered","status":"publish","type":"post","link":"https:\/\/banitoday.com\/hi\/cbse-faces-fresh-scrutiny-after-teen-researcher-alleges-critical-flaws-in-osm-portal-claims-class-12-marks-could-be-altered\/","title":{"rendered":"CBSE faces fresh scrutiny after teen researcher alleges critical flaws in OSM portal, claims Class 12 marks could be altered"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<div class=\"e9jwa\">\n<div class=\"vdo_embedd\">\n<div class=\"GfdvZ\">\n<section class=\"_bIDB  clearfix id-r-component leadmedia undefined undefined  E9tg9 \" style=\"top:0px\">\n<div class=\"_bIDB\" data-ua-type=\"1\" onclick=\"stpPgtnAndPrvntDefault(event)\">\n<div class=\"ypVvZ\">\n<div class=\"WGttI\"><img src=\"https:\/\/static.toiimg.com\/thumb\/msid-131330686,imgsize-48436,width-400,height-225,resizemode-4\/cbse-osm-portal-hack.jpg\" alt=\"CBSE faces fresh scrutiny after teen researcher alleges critical flaws in OSM portal, claims Class 12 marks could be altered\" title=\"CBSE's troubles deepen as teen hacker claims marks could be altered through OSM loopholes. (Getty Images)\" decoding=\"async\" fetchpriority=\"high\"\/><\/div>\n<\/div>\n<\/div>\n<div class=\"Ta7d_ img_cptn\"><span title=\"CBSE's troubles deepen as teen hacker claims marks could be altered through OSM loopholes. (Getty Images)\">CBSE&#8217;s troubles deepen as teen hacker claims marks could be altered through OSM loopholes. (Getty Images)<\/span><\/div>\n<\/section>\n<\/div><\/div>\n<\/div>\n<p>NEW DELHI: Even as the Central Board of Secondary Education (CBSE) continues facing criticism over answer sheet mix-ups, portal crashes and payment glitches in the Class 12 post-result process, a fresh controversy has now emerged around the security of its newly introduced On-Screen Marking (OSM) system.<span class=\"id-r-component br\" data-pos=\"2\"\/>A 19-year-old cybersecurity researcher, Nisarga Adhikary, has alleged that he discovered multiple critical vulnerabilities in CBSE\u2019s OSM portal that could potentially allow unauthorised access to examiner accounts, password resets and even modification of students\u2019 marks. The claims, published in a detailed technical blog post and amplified widely on X, have triggered fresh concerns over the board\u2019s digital preparedness after weeks of complaints from students over mismatched answer sheets, blurred scans and evaluation discrepancies.<span class=\"id-r-component br\" data-pos=\"6\"\/><span class=\"id-r-component br\" data-pos=\"8\"\/><span class=\"strong\" data-ua-type=\"1\" onclick=\"stpPgtnAndPrvntDefault(event)\">Teen researcher details alleged flaws in CBSE evaluation portal<\/span><span class=\"id-r-component br\" data-pos=\"10\"\/>In his blog titled \u201c<a href=\"https:\/\/ni5arga.com\/blog\/posts\/hacking-cbse\/\" rel=\"noopener nofollow noreferrer\" styleobj=\"[object Object]\" class=\"\" target=\"_blank\" commonstate=\"[object Object]\" frmappuse=\"1\">Exposing Critical Vulnerabilities in CBSE\u2019s On-Screen Marking Portal<\/a>\u201d, Adhikary claimed he discovered the issues on February 25 and reported them to CERT-In before making them public.<span class=\"id-r-component br\" data-pos=\"14\"\/><span class=\"id-r-component br\" data-pos=\"16\"\/>\u201cI was able to log in as an examiner and reach the evaluation dashboard, where I could view and edit marks,\u201d he wrote.<span class=\"id-r-component br\" data-pos=\"18\"\/>According to the blog, the alleged vulnerabilities included a \u201chardcoded master password\u201d visible inside the portal\u2019s JavaScript bundle, client-side OTP validation, missing route protections, password reset flaws and what he described as a \u201csystemic IDOR vulnerability\u201d.<span class=\"id-r-component br\" data-pos=\"22\"\/><\/p>\n<div data-pos=\"0\" class=\"id-r-component iIpbx undefined  &#10;        \">\n<div><img decoding=\"async\" alt=\"CBSE cybersecurity flaw\" msid=\"131330725\" width=\"\" title=\"\" placeholdersrc=\"https:\/\/static.toiimg.com\/photo\/83033472.cms\" imgsize=\"\" resizemode=\"4\" offsetvertical=\"0\" placeholdermsid=\"47529300\" type=\"thumb\" class=\"\" src=\"https:\/\/static.toiimg.com\/photo\/msid-131330725\/cbse-cybersecurity-flaw.jpg\" data-api-prerender=\"true\"\/><\/div>\n<\/div>\n<p><span class=\"id-r-component br\" data-pos=\"24\"\/>\u201cOne of the hardest things was not exploitation,\u201d he wrote, \u201cThe hardest part was reading a JavaScript file and editing a couple of values in DevTools.\u201d<span class=\"id-r-component br\" data-pos=\"26\"\/>Adhikary also alleged that OTP verification was effectively meaningless because \u201cthe browser grades its own test\u201d.<span class=\"id-r-component br\" data-pos=\"28\"\/><span class=\"id-r-component br\" data-pos=\"30\"\/>\u201cA security control that runs on the attacker\u2019s machine isn\u2019t a control at all,\u201d he wrote.<span class=\"id-r-component br\" data-pos=\"32\"\/><span class=\"strong\" data-ua-type=\"1\" onclick=\"stpPgtnAndPrvntDefault(event)\">Claims surface amid growing scrutiny of OSM rollout<\/span><span class=\"id-r-component br\" data-pos=\"34\"\/>The controversy comes days after CBSE admitted that a Delhi student, Vedant Shrivastava, had received another student\u2019s Physics answer sheet under his roll number due to a technical error in the OSM-linked scanning process.<span class=\"id-r-component br\" data-pos=\"37\"\/>The board later acknowledged the mistake and sent the correct answer sheet to the student.<span class=\"id-r-component br\" data-pos=\"39\"\/>The OSM system was introduced for Class 12 evaluations this year as part of CBSE\u2019s push towards digital assessment and faster post-result processing.<span class=\"id-r-component br\" data-pos=\"41\"\/>Software engineer Deedy Das, reacting to Adhikary\u2019s findings on X, wrote: \u201cA 19-year old broke into India\u2019s largest high school examination system of 2M+ students a year, the CBSE, and was able to view and CHANGE any students\u2019 marks.\u201d<span class=\"id-r-component br\" data-pos=\"44\"\/>Das added that the researcher had responsibly disclosed the vulnerabilities months earlier and claimed \u201cnot much has changed\u201d despite previous warnings about similar flaws in CBSE systems.<span class=\"id-r-component br\" data-pos=\"46\"\/><span class=\"id-r-component br\" data-pos=\"48\"\/><span class=\"strong\" data-ua-type=\"1\" onclick=\"stpPgtnAndPrvntDefault(event)\">CERT-In informed, website later taken offline<\/span><span class=\"id-r-component br\" data-pos=\"50\"\/>Adhikary said he reported the vulnerabilities to CERT-In and received an acknowledgement reference number. <a href=\"https:\/\/ni5arga.com\/blog\/posts\/hacking-cbse\/\" rel=\"noopener nofollow noreferrer\" styleobj=\"[object Object]\" class=\"\" target=\"_blank\" commonstate=\"[object Object]\" frmappuse=\"1\">According to his blog<\/a>, only some issues were fixed initially.<span class=\"id-r-component br\" data-pos=\"54\"\/>\u201cMost of the vulnerabilities I reported went unpatched for a long time,\u201d he wrote.<span class=\"id-r-component br\" data-pos=\"57\"\/>Soon after the claims gained traction online, the OSM portal became inaccessible temporarily, with users reporting that the website had been taken offline.<span class=\"id-r-component br\" data-pos=\"59\"\/><span class=\"em\" data-ua-type=\"1\" onclick=\"stpPgtnAndPrvntDefault(event)\">Disclaimer: The claims regarding vulnerabilities in CBSE\u2019s On-Screen Marking (OSM) portal are based on statements made by cybersecurity researcher Nisarga Adhikary and publicly available information. CBSE has not officially confirmed the extent or impact of the alleged security flaws at the time of publication. CBSE and CERT-In responses, if any, will be updated as they become available.<\/span><span class=\"id-r-component br\" data-pos=\"61\"\/><\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/timesofindia.indiatimes.com\/education\/news\/cbse-faces-fresh-scrutiny-after-teen-researcher-alleges-critical-flaws-in-osm-portal-claims-class-12-marks-could-be-altered\/articleshow\/131330616.cms\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CBSE&#8217;s troubles deepen as teen hacker claims marks could be altered through OSM loopholes. (Getty Images) NEW DELHI: Even as the Central Board of Secondary Education (CBSE) continues facing criticism over answer sheet mix-ups, portal crashes and payment glitches in the Class 12 post-result process, a fresh controversy has now emerged around the security of [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":12827,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[264],"tags":[],"class_list":["post-12826","post","type-post","status-publish","format-standard","has-post-thumbnail","category-education"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/posts\/12826","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/comments?post=12826"}],"version-history":[{"count":0,"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/posts\/12826\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/media\/12827"}],"wp:attachment":[{"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/media?parent=12826"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/categories?post=12826"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/tags?post=12826"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}