Back

MEDIUM

pmTicket Project-Management-Software add_project.php setSync sql injection

Published Sep 23, 2026

Description

A vulnerability has been found in pmTicket Project-Management-Software up to 078fa56a782490c5059a0814f84df27984f4d7e2. This affects the function setSync of the file /ajax/add_project.php. Such manipulation of the argument conn_settings leads to sql injection. The attack may be launched remotely. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

Remediation

No remediation recorded yet.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Sep 23, 2026
Updated Sep 24, 2026
Reserved Sep 23, 2026
CISA Vulnrichment
Updated Sep 24, 2026
NVD
Status Received
Modified Sep 24, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulDB
Published Sep 23, 2026
Updated Sep 24, 2026
Exploited since n/a
EUVD-2026-85749