Authenticated SQL Injection in TorrentPier BitTorrent Tracker Engine
CVE-2025-64519

8.8HIGH

Key Information:

Vendor
CVE Published:
10 November 2025

What is CVE-2025-64519?

An SQL injection vulnerability has been identified in the moderator control panel of TorrentPier, a PHP-based BitTorrent tracker engine. This issue allows authenticated users with moderator privileges to manipulate SQL queries by providing a malicious topic_id parameter. Exploiting this vulnerability can lead to unauthorized access, modification, or deletion of sensitive database information. The vulnerability affects versions up to 2.8.8 and poses a significant risk if a moderator account is compromised. A security patch has been released to address this issue.

Affected Version(s)

torrentpier <= 2.8.8

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-64519 : Authenticated SQL Injection in TorrentPier BitTorrent Tracker Engine