CVE-2025-7886: pmTicket Project-Management-Software class.database.php getUserLanguage sql injection

Published Jul 20, 2025
·
Updated

A vulnerability, which was classified as critical, was found in pmTicket Project-Management-Software up to 2ef379da2075f4761a2c9029cf91d073474e7486. This affects the function getUserLanguage of the file classes/class.database.php. The manipulation of the argument userid leads to sql injection. It is possible to initiate the attack remotely. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Software

1 affected component
pmTicket Project-Management-Software<=2ef379da2075f4761a2c9029cf91d073474e7486

Event History

Jul 20, 2025
CVE Published
via MITRE·11:32 AM
Data Sourced
via MITRE·11:32 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Jun 24, 58473
Event
via NVD·02:21 PM

Frequently Asked Questions

1

What is the severity of CVE-2025-7886?

CVE-2025-7886 is classified as a critical severity vulnerability affecting pmTicket Project-Management-Software.

2

How does CVE-2025-7886 occur?

CVE-2025-7886 occurs due to the manipulation of the user_id argument in the getUserLanguage function of the file classes/class.database.php.

3

What are the affected versions related to CVE-2025-7886?

CVE-2025-7886 affects pmTicket Project-Management-Software versions up to 2ef379da2075f4761a2c9029cf91d073474e7486.

4

How do I fix CVE-2025-7886?

To fix CVE-2025-7886, you should update pmTicket Project-Management-Software to a version that includes the security patch.

5

What is the impact of CVE-2025-7886 on the system?

The impact of CVE-2025-7886 can lead to SQL injection vulnerabilities which may allow an attacker to manipulate the database.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203