Greek student data leak: Vulnerability in UniverSIS! A SQL injection (SQLi) vulnerability in an open source developed by Greek universities to manage Greek student data left academic grades exposed.
The vulnerability in the app, UniverSIS, could allow hackers to gain access to student IDs, names, parents' names, social security numbers, home addresses and cell phones, according to a blog post published by security researcher Stavros Mekesis.

The platform's administrators released a patch to GitLab a day after they were notified of the flaw (tracked as CVE-2022-29603).
Greek student data leak: Millions of users exposed!
UniverSIS is a Student Information System (SIS) used by some of the largest universities in Greece, including the much larger Aristotle University of Thessaloniki, to store and manage personal identification information, exam results, and other sensitive student data.
“The platform also handles inactive students and inactive employees,” Mekesis told Daily Swig. “So it would be a safe estimate to say that the platform has data on millions of users.”
Although the complexity of the attack is low, the hacker must be authenticated, albeit with low privileges, such as those of a student, according to Mekesis.
“However, since many students tend to reuse passwords, when these passwords are compromised, they can be used to log into UniverSIS and exploit the SQLi vulnerability,” Mekesis warned. “Furthermore, phishing is a relatively cheap and effective form of attack.”

The UniverSIS SQLi issue involved the $select parameter and affected multiple API endpoints, including /api/students/me/messages/, due to improper validation of user-supplied input.
After sending specially crafted SQL statements to a vulnerable endpoint, the hacker could "view, add, modify, or delete information in the back-end database ," according to the security researcher.
UniverSIS versions up to and including 1.2.1 are all potentially vulnerable. Mekesis has advised users to apply a recent patch as soon as possible.
Leak of Greek student data: What is the Ministry of Education doing?
The vulnerability proves that Greek academic institutions are not investing in the security and strengthening of their information infrastructure, even now two years after the “forced” transfer of the educational system to the digital world due to the COVID-19. The management and security of information systems, which is “gold” for hackers due to the huge volume of sensitive information of Greek citizens, still remains the second and third priority for the Rectors and the authorities who choose not to staff the IT team with properly trained professionals, while in many cases the obligations of maintaining information systems fall solely on students. Perhaps it is time for a synergy between the Ministry of Education and the Ministry of Digital Governance with the aim of better organizing the critical infrastructures of academic institutions and staffing them with a workforce that can guarantee the smooth operation of the systems and safeguard against risks and attacks!
Should the Personal Data Protection Authority investigate the possibility of a leak and the use of vulnerabilities by malicious users?
*SecNews thanks the reader - who wishes to remain anonymous - for reporting the incident for the purpose of highlighting it.
