SQL Injection Vulnerability in pmTicket Project-Management Software
CVE-2025-7886
What is CVE-2025-7886?
A SQL injection vulnerability exists in the pmTicket Project-Management Software, specifically within the getUserLanguage function in the class.database.php file. By manipulating the user_id argument, an attacker can execute malicious SQL queries, potentially compromising the system's database. This vulnerability can be exploited remotely without the need for prior authentication. The rolling release approach of pmTicket complicates tracking specific affected versions, as continuous updates may obscure which releases are vulnerable or patched.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Project-Management-Software 2ef379da2075f4761a2c9029cf91d073474e7486
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
