(01) - CybersecurityDMSA-2025-IN-001

Email Exposure Vulnerability in e-Nidhi Bihar Portal

An automated scan detected that the e-Nidhi Bihar Portal potentially exposed users' email addresses to unauthorized access due to a security misconfiguration.

16 October 20252 min readCybersecurityReports

Executive Summary

Dymo's automated vulnerability scanning detected a security issue in the e-Nidhi Bihar Portal (e-nidhi.bihar.gov.in) that could potentially expose users' email addresses to unauthorized access. This type of vulnerability, while not as severe as direct code execution, creates significant risks for targeted phishing and identity-based attacks.

Affected System

  • Portal: e-Nidhi Bihar
  • URL: e-nidhi.bihar.gov.in
  • Organization: Government of Bihar, India
  • Purpose: Treasury and financial management system

Vulnerability Details

Type

Email Address Exposure / Information Disclosure

Severity

Medium (CVSS 5.3)

Technical Description

The vulnerability allows unauthorized users to access email addresses through:

  1. API Endpoint Exposure: User email data accessible without authentication
  2. Insufficient Access Controls: Lack of proper authorization checks
  3. Data Enumeration: Ability to query specific users by ID
  4. Information Leakage: Email patterns exposed in responses

Risk Assessment

Exposed email addresses enable:

  • Spear Phishing: Targeted attacks using official-looking emails
  • Social Engineering: Personalized attacks based on portal usage
  • Credential Stuffing: Testing stolen credentials on other services
  • Account Takeover: Password reset attacks using exposed information

Responsible Disclosure

This finding has been reported to:

  • e-Nidhi Portal Administrators
  • Bihar Government IT Security Team
  • National Information Centre (NIC)
  1. Implement proper authentication on all API endpoints
  2. Add rate limiting to prevent enumeration
  3. Remove email addresses from non-essential API responses
  4. Implement proper authorization checks
  5. Add security headers to prevent information leakage

This vulnerability was identified through Dymo's automated security assessment of government portals.