-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from get_tracks() in functions.php using unserialize($_COOKIE[$c_name]). The commit diff shows this was replaced with json_decode() to mitigate deserialization risks. The CVE description explicitly references this function as the entry point for the exploit, and the provided PoC demonstrates cookie manipulation (bb_t) triggers the vulnerability. While other functions like get_sessiondata() in User.php were also patched, the advisory focuses on get_tracks() as the primary attack vector.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| torrentpier/torrentpier | composer | <= 2.4.3 |
KEV Misses 88% of Exploited CVEs- Get the report