Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 24 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 23 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in pmTicket Project-Management-Software up to 078fa56a782490c5059a0814f84df27984f4d7e2. This affects the function setSync of the file /ajax/add_project.php. Such manipulation of the argument conn_settings leads to sql injection. The attack may be launched remotely. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | pmTicket Project-Management-Software add_project.php setSync sql injection | |
| First Time appeared |
Pmticket
Pmticket project-management-software |
|
| Weaknesses | CWE-74 CWE-89 |
|
| CPEs | cpe:2.3:a:pmticket:project-management-software:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pmticket
Pmticket project-management-software |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-24T13:19:14.016Z
Reserved: 2026-09-23T15:52:20.491Z
Link: CVE-2026-96751
Updated: 2026-09-24T13:18:54.085Z
Status : Received
Published: 2026-09-24T00:17:23.170
Modified: 2026-09-24T14:18:20.973
Link: CVE-2026-96751
No data.
OpenCVE Enrichment
Updated: 2026-09-24T01:00:13Z