Torrentpier version 2.4.1 allows executing arbitrary commands on the server.
This is possible because the application is vulnerable to insecure deserialization.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: Fluid Attacks
Published: 2024-02-19T23:49:28.471Z
Updated: 2024-02-19T23:49:28.471Z
Reserved: 2024-02-19T23:43:14.777Z
Link: CVE-2024-1651
JSON object: View
NVD Information
Status : Awaiting Analysis
Published: 2024-02-20T00:15:14.847
Modified: 2024-02-20T19:50:53.960
Link: CVE-2024-1651
JSON object: View
Redhat Information
No data.
CWE