CVE-2025-70146: Critical severity Projectworlds Online Time Table Generator vulnerability
Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting records) via direct HTTP requests to affected endpoints without a valid session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-70146?
CVE-2025-70146 is classified as a critical vulnerability due to the potential for unauthorized administrative operations.
How do I fix CVE-2025-70146?
To fix CVE-2025-70146, implement authentication mechanisms for the administrative action scripts in ProjectWorlds Online Time Table Generator.
What type of attacks can CVE-2025-70146 enable?
CVE-2025-70146 can enable remote attackers to add and delete records through unauthorized access to administrative endpoints.
Which versions of ProjectWorlds Online Time Table Generator are affected by CVE-2025-70146?
CVE-2025-70146 affects version 1.0 of ProjectWorlds Online Time Table Generator.
Is user data at risk due to CVE-2025-70146?
Yes, user data is at risk because attackers can manipulate records without proper authentication.