CVE-2025-3040
Last modified
CVE-2025-3040 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability was found in Project Worlds Online Time Table Generator 1.0. It has been rated as critical. EPSS estimates a 0.54% chance of exploitation in the next 30 days.
Description
A vulnerability was found in Project Worlds Online Time Table Generator 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/add_student.php. The manipulation of the argument pic leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Projectworlds | Online Time Table Generator | 1.0 |
References
- https://github.com/ydnd/cve/issues/11Exploit, Issue Tracking, Third Party Advisory
- https://vuldb.com/?ctiid.302102Permissions Required, VDB Entry
- https://vuldb.com/?id.302102Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.524934Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-3040?
How severe is CVE-2025-3040?
How do I fix CVE-2025-3040?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-30392Improper authorization in Azure Bot Framework SDK allows an …9.8
- CVE-2025-30393Use after free in Microsoft Office Excel allows an unauthori…7.8
- CVE-2025-30394Sensitive data storage in improperly locked memory in Remote…5.9
- CVE-2025-30397Access of resource using incompatible type ('type confusion'…7.5
- CVE-2025-30398Missing authorization in Nuance PowerScribe allows an unauth…8.1
- CVE-2025-30399Untrusted search path in .NET and Visual Studio allows an un…7.5
- CVE-2025-30400Use after free in Windows DWM allows an authorized attacker …7.8
- CVE-2025-30401A spoofing issue in WhatsApp for Windows prior to version 2.…6.7
- CVE-2025-30402A heap-buffer-overflow vulnerability in the loading of Execu…8.1
- CVE-2025-30403A heap-buffer-overflow vulnerability is possible in mvfst vi…8.1
- CVE-2025-30404An integer overflow vulnerability in the loading of ExecuTor…9.8
- CVE-2025-30405An integer overflow vulnerability in the loading of ExecuTor…9.8
Are you affected by CVE-2025-3040?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
