{"id":"CVE-2025-70147","title":"Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtain sensitive information (including plaintext password field values) via direct HTTP GET …","summary":"Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtain sensitive information (including plaintext password field values) via direct HTTP GET …","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-306","CWE-862"],"vendor":"projectworlds","product":"online_time_table_generator","affected":["online_time_table_generator = 1.0"],"published":"2026-02-18","updated":"2026-09-08","sourceUpdated":"2026-09-08T20:17:27.663","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-70147","references":[{"url":"https://0x0bito.github.io/posts/CVE-2025-70147-OTTTG-Info-Disclosure/","label":"cve@mitre.org"},{"url":"https://projectworlds.com/online-time-table-generator-php-mysql/","label":"cve@mitre.org"},{"url":"https://youngkevinn.github.io/posts/CVE-2025-70147-OTTTG-Info-Disclosure/","label":"cve@mitre.org"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-02-18T18:34:10.573179Z"},"epss":0.00518,"epssPercentile":0.42878,"ingestedAt":"2026-09-08T20:10:03.220Z","slug":"CVE-2025-70147","body":"## Overview\n\nMissing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtain sensitive information (including plaintext password field values) via direct HTTP GET requests to these endpoints without a valid session.\n\n## Affected\n\n- `online_time_table_generator = 1.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":53,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}