CVE-2024-1651
CRITICALTorrentpier - Insecure Deserialization
Title source: ruleDescription
Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to insecure deserialization.
Exploits (4)
Scores
CVSS v3
10.0
EPSS
0.8059
EPSS Percentile
99.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (2)
torrentpier/torrentpier
torrentpier/torrentpier
Packagist
Timeline
Published
Feb 20, 2024
Tracked Since
Feb 18, 2026