Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to insecure deserialization.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://github.com/torrentpier/torrentpier | product |
https://fluidattacks.com/advisories/xavi/ | third party advisory exploit |