Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      The Ultimate Guide to Node.js Development Pricing for Enterprises

      July 29, 2025

      Stack Overflow: Developers’ trust in AI outputs is worsening year over year

      July 29, 2025

      Web Components: Working With Shadow DOM

      July 28, 2025

      Google’s new Opal tool allows users to create mini AI apps with no coding required

      July 28, 2025

      I replaced my Samsung OLED TV with this Sony Mini LED model for a week – and didn’t regret it

      July 29, 2025

      I tested the most popular robot mower on the market – and it was a $5,000 crash out

      July 29, 2025

      5 gadgets and accessories that leveled up my gaming setup (including a surprise console)

      July 29, 2025

      Why I’m patiently waiting for the Samsung Z Fold 8 next year (even though the foldable is already great)

      July 29, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Performance Analysis with Laravel’s Measurement Tools

      July 29, 2025
      Recent

      Performance Analysis with Laravel’s Measurement Tools

      July 29, 2025

      Memoization and Function Caching with this PHP Package

      July 29, 2025

      Laracon US 2025 Livestream

      July 29, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Microsoft mysteriously offered a Windows 11 upgrade to this unsupported Windows 10 PC — despite it failing to meet the “non-negotiable” TPM 2.0 requirement

      July 29, 2025
      Recent

      Microsoft mysteriously offered a Windows 11 upgrade to this unsupported Windows 10 PC — despite it failing to meet the “non-negotiable” TPM 2.0 requirement

      July 29, 2025

      With Windows 10’s fast-approaching demise, this Linux migration tool could let you ditch Microsoft’s ecosystem with your data and apps intact — but it’s limited to one distro

      July 29, 2025

      Windows 10 is 10 years old today — let’s look back at 10 controversial and defining moments in its history

      July 29, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»AIIMS ORBO Portal Vulnerability Leads to Massive Data Exposure

    AIIMS ORBO Portal Vulnerability Leads to Massive Data Exposure

    July 28, 2025

    AIIMS portal Vulnerability

    A critical vulnerability in the AIIMS portal exposed highly sensitive data of voluntary organ and tissue donors registered with the Organ Retrieval Banking Organisation (ORBO). The AIIMS portal vulnerability allowed unauthorized access to personally identifiable and medical information of donors across India. This vulnerability was discovered in mid-May 2025 by independent cybersecurity researcher Aniket Tomar. ORBO is a key facility of the All India Institute of Medical Sciences (AIIMS), New Delhi. 

    The AIIMS portal vulnerability, if left unpatched, had the potential to severely undermine data privacy, public trust, and the security of the national digital health infrastructure.

    ORBO, as the nodal body for cadaver organ and tissue donation activities at AIIMS, maintains a brain death donor registry and coordinates transplants, making the exposed data particularly sensitive. 

    Decoding the AIIMS Portal Vulnerability and Data Exposure 

    According to Tomar, his investigation revealed that the vulnerability in the AIIMS portal provided unrestricted access to a vast amount of private data, including full names, residential addresses, phone numbers, email addresses, blood groups, donated organs, tissues, donor age, and even witness information. This data could be accessed without any form of authentication. 

    “I was able to view several lakh donor entries. The data wasn’t just from Delhi—entries covered donors from multiple regions across India,” Tomar told The Hindu. “The scope of the exposure points to a nationwide data breach affecting individuals who placed their trust in a reputed health institution.” 

    Among the most critical data fields exposed were: 

    1. Personally Identifiable Information (PII): Full names, mobile numbers, email addresses, residential addresses.
    2. Medical Information: Donated organs, blood types, tissues, and donor age.
    3. Witness Details: Contact and identification information of witnesses to the donation process.

    CERT’s Intervention and Fix 

    Tomar promptly reported the issue to the Computer Emergency Response Team (CERT-IN) with a detailed Proof of Concept (PoC) and recommendations for fixing the flaw. In his email, he stressed that the breach not only compromised personal information but also violated the Digital Personal Data Protection (DPDP) Act, 2023. 

    “This is more than just a technical issue—it’s an ethical lapse. It impacts organ donors who expect the highest levels of confidentiality and data stewardship. Public trust in digital health platforms must not be taken for granted,” Tomar warned in his communication with CERT. 

    Following Tomar’s disclosure, CERT acknowledged the issue and worked with AIIMS to resolve the flaw. By June 18, 2025, the vulnerability was successfully mitigated, and public access to sensitive data was blocked. CERT officially thanked Tomar for his responsible disclosure. 

    Conclusion 

    Tomar urged AIIMS and other government bodies to audit their digital health platforms for similar vulnerabilities and to promptly notify affected individuals, as required by the DPDP Act. He stressed that personally identifiable information should never be exposed on public-facing systems, particularly in healthcare. 

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleAllianz Life Confirms Major Data Breach via Third-Party Cloud Platform
    Next Article Scattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. Infrastructure

    Related Posts

    Development

    Performance Analysis with Laravel’s Measurement Tools

    July 29, 2025
    Development

    Memoization and Function Caching with this PHP Package

    July 29, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    Everwild’s cancellation has me worried for one of my favorite dev teams and Xbox itself — It needs creative new games to thrive and refresh its identity

    News & Updates

    CVE-2025-47682 – Cozy Vision Technologies Pvt. Ltd. SMS Alert Order Notifications – WooCommerce SQL Injection

    Common Vulnerabilities and Exposures (CVEs)

    Precise Number Formatting with Laravel’s Enhanced Number::spell Method

    Development

    Players aren’t buying Call of Duty’s “error” excuse for the ads Activision started forcing into the game’s menus recently

    News & Updates

    Highlights

    Linux

    Rilasciata KDE Frameworks 6.14: Novità e approfondimento sulla raccolta di librerie per Qt

    May 10, 2025

    KDE Frameworks è una raccolta di oltre 80 librerie aggiuntive pensate per estendere le funzionalità…

    CVE-2025-4023 – iSourcecode Placement Management System SQL Injection

    April 28, 2025

    Mistral AI Introduces Mistral Code: A Customizable AI Coding Assistant for Enterprise Workflows

    June 4, 2025

    Warning: Protect your phone from choicejacking before it’s too late – here’s how

    July 29, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.