{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-96751", "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "state": "PUBLISHED", "assignerShortName": "VulDB", "dateReserved": "2026-09-23T15:52:20.491Z", "datePublished": "2026-09-23T23:30:11.506Z", "dateUpdated": "2026-09-23T23:30:11.506Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "shortName": "VulDB", "dateUpdated": "2026-09-23T23:30:11.506Z" }, "title": "pmTicket Project-Management-Software add_project.php setSync sql injection", "problemTypes": [ { "descriptions": [ { "type": "CWE", "cweId": "CWE-89", "lang": "en", "description": "SQL Injection" } ] }, { "descriptions": [ { "type": "CWE", "cweId": "CWE-74", "lang": "en", "description": "Injection" } ] } ], "affected": [ { "vendor": "pmTicket", "product": "Project-Management-Software", "versions": [ { "version": "078fa56a782490c5059a0814f84df27984f4d7e2", "status": "affected" } ], "cpes": [ "cpe:2.3:a:pmticket:project-management-software:*:*:*:*:*:*:*:*" ] } ], "descriptions": [ { "lang": "en", "value": "A vulnerability has been found in pmTicket Project-Management-Software up to 078fa56a782490c5059a0814f84df27984f4d7e2. This affects the function setSync of the file /ajax/add_project.php. Such manipulation of the argument conn_settings leads to sql injection. The attack may be launched remotely. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way." } ], "metrics": [ { "cvssV4_0": { "version": "4.0", "baseScore": 6.9, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P", "baseSeverity": "MEDIUM" } }, { "cvssV3_1": { "version": "3.1", "baseScore": 7.3, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R", "baseSeverity": "HIGH" } }, { "cvssV3_0": { "version": "3.0", "baseScore": 7.3, "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R", "baseSeverity": "HIGH" } }, { "cvssV2_0": { "version": "2.0", "baseScore": 7.5, "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR" } } ], "timeline": [ { "time": "2026-09-23T00:00:00.000Z", "lang": "en", "value": "Advisory disclosed" }, { "time": "2026-09-23T02:00:00.000Z", "lang": "en", "value": "VulDB entry created" }, { "time": "2026-09-23T17:57:25.000Z", "lang": "en", "value": "VulDB entry last update" } ], "credits": [ { "lang": "en", "value": "Allan Njuguna (VulDB User)", "type": "reporter" }, { "lang": "en", "value": "VulDB CNA Team", "type": "coordinator" } ], "references": [ { "url": "https://vuldb.com/vuln/409005", "name": "VDB-409005 | pmTicket Project-Management-Software add_project.php setSync sql injection", "tags": [ "vdb-entry", "technical-description" ] }, { "url": "https://vuldb.com/vuln/409005/cti", "name": "VDB-409005 | CTI Indicators (IOB, IOC, TTP, IOA)", "tags": [ "signature", "permissions-required" ] }, { "url": "https://vuldb.com/cve/CVE-2026-96751", "name": "CVE-2026-96751 | CVE Analysis and Report", "tags": [ "third-party-advisory" ] }, { "url": "https://vuldb.com/submit/904342", "name": "Submit #904342 | pmTicket Project-Management-Software(https://github.com/issue-tracking-system/Project-Management-Software) commit : cd6e519d507cdd4d63061300bf60fb176e1f57e0 SQL Injection", "tags": [ "third-party-advisory" ] }, { "url": "https://asciinema.org/a/1230576", "tags": [ "broken-link" ] } ], "x_generator": [ "VulDB PVTS v202609" ] } } }