PT-2026-42626 · Packagist · Torrentpier/Torrentpier

Publicado

2026-05-11

·

Atualizado

2026-05-11

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.

Summary

Hi, there. We've found PHP Serialize Injections in your project “torrentpier". According to the OWASP, it can pose a significant risk: enable an attacker to modify serialized objects in order to inject malicious data into the application code, resulting in code execution or an arbitrary reading of the file on any vulnerable system.

Details

In the attachment you can find a report with the number of vulnerabilities, their types and the vulnerable files. To view the lines of vulnerable code you may scan your project with the "[PHP Secure](https://phpsecure.net/?utm source=github&utm term=torrentpier&utm content=torrentpier)" vulnerability scanner with a full access to it.

PoC

Screenshot 2023-09-25 at 11 12 32 AM Screenshot 2023-09-25 at 11 12 43 AM Screenshot 2023-09-25 at 11 12 53 AM Screenshot 2023-09-25 at 11 13 13 AM

About Us

We are a team of developers of the PHP Secure vulnerability scanner. First, we checked your code automatically. Then we reviewed the vulnerable code more deeply manually and felt it was necessary to report about it to you. We suggest you scanning your code and address vulnerabilities as soon as possible to prevent a potential breach.
If you have any questions, email us at support@phpsecure.net"

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-H29G-C9CX-C73Q

Produtos afetados

Torrentpier/Torrentpier