CVE-2025-11135 (CNNVD-202509-4424)
中文标题:
PMTicket Project-Management-Software 代码问题漏洞
英文标题:
pmTicket Project-Management-Software Cookie class.database.php loadLanguage deserialization
漏洞描述
中文描述:
PMTicket Project-Management-Software是PMTicket开源的一款敏捷项目管理与问题跟踪系统。 PMTicket Project-Management-Software存在代码问题漏洞,该漏洞源于对文件classes/class.database.php中组件Cookie Handler的参数user_id的错误操作,可能导致反序列化攻击。
英文描述:
A vulnerability was detected in pmTicket Project-Management-Software up to 2ef379da2075f4761a2c9029cf91d073474e7486. The affected element is the function loadLanguage of the file classes/class.database.php of the component Cookie Handler. Performing manipulation of the argument user_id results in deserialization. The attack can be initiated remotely. The exploit is now public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| pmTicket | Project-Management-Software | 2ef379da2075f4761a2c9029cf91d073474e7486 | - | - |
cpe:2.3:a:pmticket:project-management-software:2ef379da2075f4761a2c9029cf91d073474e7486:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
cve.org
cve.org
CVSS评分详情
4.0 (cna)
MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
3.1 (cna)
HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
3.0 (cna)
HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
2.0 (cna)
HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-11135 |
2025-11-11 15:23:02 | 2025-11-11 07:40:05 |
| NVD | nvd_CVE-2025-11135 |
2025-11-11 15:01:04 | 2025-11-11 07:47:56 |
| CNNVD | cnnvd_CNNVD-202509-4424 |
2025-11-11 15:12:59 | 2025-11-11 08:00:14 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 代码问题
- cnnvd_id: 未提取 -> CNNVD-202509-4424
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- data_sources: ['cve'] -> ['cve', 'nvd']