CVE-2025-70147

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
18/02/2026
Last modified:
20/02/2026

Description

Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtain sensitive information (including plaintext password field values) via direct HTTP GET requests to these endpoints without a valid session.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:projectworlds:online_time_table_generator:1.0:*:*:*:*:*:*:*