10
CVE-2024-1651
- EPSS 77.8%
- Veröffentlicht 20.02.2024 00:15:14
- Zuletzt bearbeitet 12.02.2025 17:26:55
- Quelle help@fluidattacks.com
- CVE-Watchlists
- Unerledigt
Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to insecure deserialization.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Torrentpier ≫ Torrentpier Version2.4.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 77.8% | 0.989 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| help@fluidattacks.com | 10 | 3.9 | 6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.