CVE-2025-70146

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
18/02/2026
Last modified:
20/02/2026

Description

Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting records) via direct HTTP requests to affected endpoints without a valid session.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:projectworlds:online_time_table_generator:1.0:*:*:*:*:*:*:*