Skip to content

torrentpier has PHP Serialize Injections

Critical severity GitHub Reviewed Published Jul 13, 2024 in torrentpier/torrentpier • Updated May 11, 2026

Package

composer torrentpier/torrentpier (Composer)

Affected versions

<= 2.4.3

Patched versions

2.4.4

Description

Summary

Hi, there. We've found PHP Serialize Injections in your project “torrentpier". According to the OWASP, it can pose a significant risk: enable an attacker to modify serialized objects in order to inject malicious data into the application code, resulting in code execution or an arbitrary reading of the file on any vulnerable system.

Details

In the attachment you can find a report with the number of vulnerabilities, their types and the vulnerable files. To view the lines of vulnerable code you may scan your project with the "PHP Secure" vulnerability scanner with a full access to it.

PoC

Screenshot 2023-09-25 at 11 12 32 AM

Screenshot 2023-09-25 at 11 12 43 AM

Screenshot 2023-09-25 at 11 12 53 AM

Screenshot 2023-09-25 at 11 13 13 AM

About Us

We are a team of developers of the PHP Secure vulnerability scanner. First, we checked your code automatically. Then we reviewed the vulnerable code more deeply manually and felt it was necessary to report about it to you. We suggest you scanning your code and address vulnerabilities as soon as possible to prevent a potential breach.

If you have any questions, email us at support@phpsecure.net"

References

@belomaxorka belomaxorka published to torrentpier/torrentpier Jul 13, 2024
Published to the GitHub Advisory Database May 11, 2026
Reviewed May 11, 2026
Last updated May 11, 2026

Severity

Critical

EPSS score

Weaknesses

Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid. Learn more on MITRE.

CVE ID

No known CVE

GHSA ID

GHSA-h29g-c9cx-c73q
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.