CVE-2025-7886: pmTicket Project-Management-Software class.database.php getUserLanguage sql injection
A vulnerability, which was classified as critical, was found in pmTicket Project-Management-Software up to 2ef379da2075f4761a2c9029cf91d073474e7486. This affects the function getUserLanguage of the file classes/class.database.php. The manipulation of the argument userid leads to sql injection. It is possible to initiate the attack remotely. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7886?
CVE-2025-7886 is classified as a critical severity vulnerability affecting pmTicket Project-Management-Software.
How does CVE-2025-7886 occur?
CVE-2025-7886 occurs due to the manipulation of the user_id argument in the getUserLanguage function of the file classes/class.database.php.
What are the affected versions related to CVE-2025-7886?
CVE-2025-7886 affects pmTicket Project-Management-Software versions up to 2ef379da2075f4761a2c9029cf91d073474e7486.
How do I fix CVE-2025-7886?
To fix CVE-2025-7886, you should update pmTicket Project-Management-Software to a version that includes the security patch.
What is the impact of CVE-2025-7886 on the system?
The impact of CVE-2025-7886 can lead to SQL injection vulnerabilities which may allow an attacker to manipulate the database.