CVE-2025-70147: High severity Projectworlds Online Time Table Generator vulnerability
Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtain sensitive information (including plaintext password field values) via direct HTTP GET requests to these endpoints without a valid session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-70147?
CVE-2025-70147 is considered a moderate severity vulnerability due to its potential for exposing sensitive information.
How does CVE-2025-70147 affect ProjectWorlds Online Time Table Generator?
CVE-2025-70147 allows attackers to obtain sensitive information from admin endpoints without authentication.
What are the potential risks of CVE-2025-70147?
The risks include unauthorized access to sensitive data such as plaintext passwords and user information.
How can I fix CVE-2025-70147?
To fix CVE-2025-70147, implement proper authentication controls on /admin/student.php and /admin/teacher.php to restrict access.
Who is affected by CVE-2025-70147?
Users of ProjectWorlds Online Time Table Generator version 1.0 are affected by CVE-2025-70147.