CVE-2025-2660: Project Worlds Online Time Table Generator index.php sql injection
A vulnerability has been found in Project Worlds Online Time Table Generator 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/index.php. The manipulation of the argument e leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2660?
CVE-2025-2660 is classified as a critical severity vulnerability due to its potential for remote SQL injection.
How do I fix CVE-2025-2660?
To fix CVE-2025-2660, update Project Worlds Online Time Table Generator to the latest version that patches the SQL injection vulnerability.
What type of attack does CVE-2025-2660 allow?
CVE-2025-2660 allows for remote SQL injection attacks, which can compromise the database.
Which file is vulnerable in CVE-2025-2660?
The vulnerable file in CVE-2025-2660 is /admin/index.php.
What is affected by CVE-2025-2660?
CVE-2025-2660 affects the Project Worlds Online Time Table Generator version 1.0.