Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 20 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:projectworlds:online_time_table_generator:1.0:*:*:*:*:*:*:* |
Thu, 19 Feb 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Projectworlds
Projectworlds online Time Table Generator |
|
| Vendors & Products |
Projectworlds
Projectworlds online Time Table Generator |
Wed, 18 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-306 CWE-862 |
|
| Metrics |
cvssV3_1
|
Wed, 18 Feb 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting records) via direct HTTP requests to affected endpoints without a valid session. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-02-18T18:37:34.885Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-70146
Updated: 2026-02-18T18:36:59.112Z
Status : Analyzed
Published: 2026-02-18T17:21:35.853
Modified: 2026-02-20T20:07:49.620
Link: CVE-2025-70146
No data.
OpenCVE Enrichment
Updated: 2026-02-19T10:20:46Z