PT-2026-20462 · Projectworlds · Online Time Table Generator
CVE-2025-70147
·
Publicado
2026-02-18
·
Atualizado
2026-02-18
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ProjectWorlds Online Time Table Generator version 1.0
Description
The application lacks proper authentication checks for specific administrative endpoints. This allows unauthenticated remote attackers to directly access sensitive information. The vulnerable endpoints are ''/admin/student.php'' and ''/admin/teacher.php''. Accessing these endpoints via direct HTTP GET requests without a valid session reveals sensitive data, including plaintext password field values.
Recommendations
Implement authentication checks for access to the ''/admin/student.php'' endpoint.
Implement authentication checks for access to the ''/admin/teacher.php'' endpoint.
Exploit
Correção
Missing Authentication
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Online Time Table Generator