Deserialization Vulnerability in pmTicket Project-Management Software
CVE-2025-11135
Key Information:
- Vendor
Pmticket
- Vendor
- CVE Published:
- 29 September 2025
Badges
What is CVE-2025-11135?
The pmTicket Project-Management Software contains a deserialization vulnerability within the loadLanguage function located in the Cookie Handler component's class.database.php file. By manipulating the user_id argument, an attacker is able to perform operations leading to potential remote exploitation. Notably, the vulnerability has been publicly disclosed, and despite early notification efforts to the vendor, no responses have been given. This software operates on a continuous delivery model with rolling releases, making it challenging to ascertain specific version impacts for updates or patches.
Affected Version(s)
Project-Management-Software 2ef379da2075f4761a2c9029cf91d073474e7486
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved