Junglewise Threat Intelligence

CVE-2026-96751: pmTicket SQL injection in setSync

CVE-2026-96751 · Severity: high · CVSS 7.3 · Published 2026-09-24

Executive brief

pmTicket is a project management software with a web-based interface. An unauthenticated attacker can inject malicious SQL commands through the setSync function in the add_project.php page, allowing them to read, modify, or delete data from the application's database without authorization.

Technical details

Unauthenticated SQL injection vulnerability in the setSync function of /ajax/add_project.php, where the conn_settings parameter is not properly sanitized before use in database queries. The attack requires network access but no authentication or user interaction. A successful exploit allows an attacker to execute arbitrary SQL commands against the backend database.

Affected products

  • pmTicket pmTicket Project-Management-Software up to commit 078fa56a782490c5059a0814f84df27984f4d7e2

Timeline

  • 2026-09-24: disclosed

References