Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 20 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:projectworlds:online_time_table_generator:1.0:*:*:*:*:*:*:* |
Thu, 19 Feb 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Projectworlds
Projectworlds online Time Table Generator |
|
| Vendors & Products |
Projectworlds
Projectworlds online Time Table Generator |
Wed, 18 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-306 CWE-862 |
|
| Metrics |
cvssV3_1
|
Wed, 18 Feb 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtain sensitive information (including plaintext password field values) via direct HTTP GET requests to these endpoints without a valid session. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-02-18T18:34:45.204Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-70147
Updated: 2026-02-18T18:33:12.887Z
Status : Analyzed
Published: 2026-02-18T17:21:36.007
Modified: 2026-02-20T20:07:38.290
Link: CVE-2025-70147
No data.
OpenCVE Enrichment
Updated: 2026-02-19T10:20:45Z