CVE-2025-3040: Project Worlds Online Time Table Generator add_student.php unrestricted upload
A vulnerability was found in Project Worlds Online Time Table Generator 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/addstudent.php. The manipulation of the argument pic leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3040?
CVE-2025-3040 has been rated as critical due to the potential for unrestricted file uploads.
How do I fix CVE-2025-3040?
To fix CVE-2025-3040, update the Project Worlds Online Time Table Generator to the latest version that addresses this vulnerability.
What specific function is affected by CVE-2025-3040?
CVE-2025-3040 affects the file /admin/add_student.php within the Project Worlds Online Time Table Generator.
What type of vulnerability is CVE-2025-3040?
CVE-2025-3040 is classified as an unrestricted file upload vulnerability.
Who is affected by CVE-2025-3040?
Users of Project Worlds Online Time Table Generator 1.0 are affected by CVE-2025-3040.