CVE-2025-3041: Project Worlds Online Time Table Generator updatestudent.php unrestricted upload
A vulnerability classified as critical has been found in Project Worlds Online Time Table Generator 1.0. This affects an unknown part of the file /admin/updatestudent.php. The manipulation of the argument pic leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3041?
CVE-2025-3041 is classified as a critical vulnerability.
What components are affected by CVE-2025-3041?
CVE-2025-3041 affects the /admin/updatestudent.php file in Project Worlds Online Time Table Generator 1.0.
What kind of attack does CVE-2025-3041 allow?
CVE-2025-3041 allows for unrestricted file upload through manipulation of the pic argument.
How can I mitigate CVE-2025-3041?
To mitigate CVE-2025-3041, ensure proper input validation and restrict file type uploads in the application.
Is there a patch for CVE-2025-3041 available?
Currently, there is no official patch available for CVE-2025-3041 from the vendor.