CPE
An unauthenticated remote SQL injection vulnerability in pmTicket Project-Management-Software allows attackers to execute arbitrary SQL commands via the 'conn_settings' parameter in /ajax/add_project.php.