Monday, August 3, 2026

Apps & Consumer

VenturEd Solutions fixes security flaw in Ravenna Hub platform

Florida-based VenturEd Solutions fixed an IDOR vulnerability in its Ravenna Hub platform that exposed slightly more than 1.63 million student records to unauthorized access.

VenturEd Solutions fixes security flaw in Ravenna Hub platform

Florida-based VenturEd Solutions develops and maintains Ravenna Hub, an admissions website platform used by families to enroll children into schools. The platform serves over a million students and processes hundreds of thousands of applications a year. Recently, the website was found to have a security flaw that allowed any logged-in user to access the personally identifiable data of other users. This security lapse exposed slightly more than 1.63 million records to unauthorized access.

The vulnerability is known as an insecure direct object reference, or IDOR—a security flaw allowing unauthorized access to data by modifying identifiers. In practice, this security lapse allowed any logged-in user to access another student’s data by modifying the unique sequential seven-digit number associated with a student’s profile in their web browser’s address bar. Because the student numbers are sequential, a user could access other records simply by changing the profile number by one or more digits.

TechCrunch first learned of the vulnerability on Wednesday and subsequently alerted the company. VenturEd Solutions fixed the security bug on the same day they were alerted. Nick Laird, the chief executive of VenturEd Solutions, confirmed the resolution in an email, stating that “the company was able to replicate the issue and has addressed the vulnerability.” While Laird noted that the company is investigating the incident, he would not commit to notifying users about the security lapse. In addition, Laird declined to comment on whether the company has the ability to check if there was any improper access to other users’ data, or if Ravenna Hub had its security checked by a third party.

This incident is the latest security lapse involving simple security flaws that affect student data. It follows a similar security lapse at the online mentoring site UStrive in January, which also exposed the personal information of its users. These back-to-back incidents underscore the persistent risks to student data in digital platforms.

Why it matters

A security vulnerability in the Ravenna Hub admissions platform exposed sensitive personal information of children and parents, highlighting ongoing risks in student data management systems.