Email Exposure Vulnerability in e-Nidhi Bihar Portal
An automated scan detected that the e-Nidhi Bihar Portal potentially exposed users' email addresses to unauthorized access due to a security misconfiguration.
Executive Summary
Dymo's automated vulnerability scanning detected a security issue in the e-Nidhi Bihar Portal (e-nidhi.bihar.gov.in) that could potentially expose users' email addresses to unauthorized access. This type of vulnerability, while not as severe as direct code execution, creates significant risks for targeted phishing and identity-based attacks.
Affected System
- Portal: e-Nidhi Bihar
- URL: e-nidhi.bihar.gov.in
- Organization: Government of Bihar, India
- Purpose: Treasury and financial management system
Vulnerability Details
Type
Email Address Exposure / Information Disclosure
Severity
Medium (CVSS 5.3)
Technical Description
The vulnerability allows unauthorized users to access email addresses through:
- API Endpoint Exposure: User email data accessible without authentication
- Insufficient Access Controls: Lack of proper authorization checks
- Data Enumeration: Ability to query specific users by ID
- Information Leakage: Email patterns exposed in responses
Risk Assessment
Exposed email addresses enable:
- Spear Phishing: Targeted attacks using official-looking emails
- Social Engineering: Personalized attacks based on portal usage
- Credential Stuffing: Testing stolen credentials on other services
- Account Takeover: Password reset attacks using exposed information
Responsible Disclosure
This finding has been reported to:
- e-Nidhi Portal Administrators
- Bihar Government IT Security Team
- National Information Centre (NIC)
Recommended Fixes
- Implement proper authentication on all API endpoints
- Add rate limiting to prevent enumeration
- Remove email addresses from non-essential API responses
- Implement proper authorization checks
- Add security headers to prevent information leakage
This vulnerability was identified through Dymo's automated security assessment of government portals.