PT-2025-14008 · Unknown · Project Worlds Online Time Table Generator

Ieeee

·

Published

2025-03-31

·

Updated

2025-07-09

·

CVE-2025-3040

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Project Worlds Online Time Table Generator version 1.0
Description A critical issue was found in the file /admin/add student.php, where the manipulation of the pic argument leads to unrestricted upload. This issue can be exploited remotely. The exploit has been disclosed to the public.
Recommendations For Project Worlds Online Time Table Generator version 1.0, consider disabling the file /admin/add student.php or restricting access to it until a patch is available. As a temporary workaround, avoid using the pic argument in the /admin/add student.php file to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-3040

Affected Products

Project Worlds Online Time Table Generator