CVE-2025-2659: Project Worlds Online Time Table Generator index.php sql injection
Published Mar 23, 2025
·Updated
A vulnerability, which was classified as critical, was found in Project Worlds Online Time Table Generator 1.0. This affects an unknown part of the file /student/index.php. The manipulation of the argument e leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Project Worlds Online Time Table Generator
Projectworlds Online Time Table Generator=1.0
Event History
Mar 23, 2025
CVE Published
via MITRE·06:31 PM
Data Sourced
via MITRE·06:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
May 20, 58462
Event
via NVD·07:00 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-2659?
CVE-2025-2659 has been classified as a critical vulnerability.
2
What type of vulnerability is CVE-2025-2659?
CVE-2025-2659 is an SQL injection vulnerability found in the Project Worlds Online Time Table Generator.
3
How do I fix CVE-2025-2659?
To fix CVE-2025-2659, you should implement proper input validation and parameterized queries to prevent SQL injection.
4
Can CVE-2025-2659 be exploited remotely?
Yes, CVE-2025-2659 can be exploited remotely.
5
Which software is affected by CVE-2025-2659?
CVE-2025-2659 affects Project Worlds Online Time Table Generator version 1.0.