{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3apmticketproject_management_software/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:pmticket:project_management_software:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-96751"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Project-Management-Software (up to commit 078fa56a782490c5059a0814f84df27984f4d7e2)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","sqli","vulnerability"],"_cs_type":"advisory","_cs_vendors":["pmTicket"],"content_html":"\u003cp\u003eA SQL injection vulnerability exists in the pmTicket Project-Management-Software, specifically affecting the 'setSync' function within the '/ajax/add_project.php' file. The vulnerability arises from improper sanitization of the 'conn_settings' input argument, allowing remote, unauthenticated attackers to inject and execute arbitrary SQL commands. This flaw affects all versions of the software up to commit hash 078fa56a782490c5059a0814f84df27984f4d7e2. As the software follows a rolling release model, there are no specific version numbers to track; users are advised to verify their current build against the latest available repository state. The vendor has remained unresponsive to disclosure attempts, necessitating proactive defensive measures by administrators hosting this application.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an unauthenticated remote attacker to gain unauthorized access to the underlying database. This can lead to the exfiltration of project-related sensitive data, manipulation of internal application state, or potential full administrative control over the application backend, depending on database permissions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eDeploy a Web Application Firewall (WAF) or equivalent monitoring solution to inspect and block HTTP requests to /ajax/add_project.php containing SQL injection payloads in the 'conn_settings' parameter.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation and parameterization for all SQL queries within the application codebase.\u003c/li\u003e\n\u003cli\u003eConduct an audit of the current application build against the latest commit hash in the upstream repository to ensure the patch is applied.\u003c/li\u003e\n\u003cli\u003eEnsure the database user account utilized by the pmTicket application is restricted to the minimum necessary privileges (Principle of Least Privilege) to minimize the impact of potential SQL injection exploitation.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-24T00:45:37Z","date_published":"2026-09-24T00:45:37Z","id":"https://feed.craftedsignal.io/briefs/2026-09-pmticket-sql-injection/","summary":"An unauthenticated remote SQL injection vulnerability in pmTicket Project-Management-Software allows attackers to execute arbitrary SQL commands via the 'conn_settings' parameter in /ajax/add_project.php.","title":"SQL Injection in pmTicket Project-Management-Software","url":"https://feed.craftedsignal.io/briefs/2026-09-pmticket-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:pmticket:project_management_software:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}