CVE-2025-70146 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perfo…
Critical CVSS: 9.1

CVE-2025-70146

Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting records) via direct HTTP requests to affected endpoints without a valid session.
Vendor
Projectworlds
Product
Online Time Table Generator
CWE
CWE-306
Yayın Tarihi
2026-02-18 17:21:35
Güncelleme
2026-02-20 20:07:49
Source Identifier
cve@mitre.org
KEV Date Added
-

Kategoriler

Referanslar