CVE-2024-1651

CRITICAL

Torrentpier - Insecure Deserialization

Title source: rule

Description

Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to insecure deserialization.

Exploits (4)

nomisec WORKING POC 14 stars
by sharpicx · poc
https://github.com/sharpicx/CVE-2024-1651-PoC
nomisec WORKING POC 3 stars
by hy011121 · poc
https://github.com/hy011121/CVE-2024-1651-exploit-RCE
nomisec WORKING POC
by killukeren · poc
https://github.com/killukeren/cve-2024-1651
nomisec WORKING POC
by Whiteh4tWolf · poc
https://github.com/Whiteh4tWolf/CVE-2024-1651-PoC

Scores

CVSS v3 10.0
EPSS 0.8059
EPSS Percentile 99.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (2)

torrentpier/torrentpier
torrentpier/torrentpier Packagist

Timeline

Published Feb 20, 2024
Tracked Since Feb 18, 2026