10
CVSSv3

CVE-2024-1651

Published: 20/02/2024 Updated: 20/02/2024
CVSS v3 Base Score: 10 | Impact Score: 6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to insecure deserialization.

Vulnerability Trend

Github Repositories

Torrentpier v2.4.1. CVE-2024-1651. Remote Code Execution (RCE). Exploit.

CVE-2024-1651 This CVE was discovered by Carlos Bello from the Fluid Attack Offensive Team The finding discusses Insecure Object Deserialization to obtain RCE (Remote Code Execution) Here, I have created a faster and easier-to-use PoC (Proof of Concept) Therefore, if anyone wants to reproduce the finding, they can use this as a reference example Preview

CVE-2024-1651 This CVE was discovered by Carlos Bello from the Fluid Attack Offensive Team The finding discusses Insecure Object Deserialization to obtain RCE (Remote Code Execution) Here, I have created a faster and easier-to-use PoC (Proof of Concept) Therefore, if anyone wants to reproduce the finding, they can use this as a reference example Preview