{"id":"CVE-2025-70146","title":"Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting reco…","summary":"Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting reco…","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","cwe":["CWE-306","CWE-862"],"vendor":"projectworlds","product":"online_time_table_generator","affected":["online_time_table_generator = 1.0"],"published":"2026-02-18","updated":"2026-09-08","sourceUpdated":"2026-09-08T20:17:27.477","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-70146","references":[{"url":"https://0x0bito.github.io/posts/CVE-2025-70146-OTTTG-Unauth-Deletion/","label":"cve@mitre.org"},{"url":"https://projectworlds.com/online-time-table-generator-php-mysql/","label":"cve@mitre.org"},{"url":"https://youngkevinn.github.io/posts/CVE-2025-70146-OTTTG-Unauth-Deletion/","label":"cve@mitre.org"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-02-18T18:36:27.648790Z"},"epss":0.00571,"epssPercentile":0.45733,"ingestedAt":"2026-09-08T20:10:03.220Z","slug":"CVE-2025-70146","body":"## Overview\n\nMissing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting records) via direct HTTP requests to affected endpoints without a valid session.\n\n## Affected\n\n- `online_time_table_generator = 1.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":62,"depthScoreParts":{"impact":50.1,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}