Authenticated SQL Injection in TorrentPier BitTorrent Tracker Engine
CVE-2025-64519
8.8HIGH
What is CVE-2025-64519?
An SQL injection vulnerability has been identified in the moderator control panel of TorrentPier, a PHP-based BitTorrent tracker engine. This issue allows authenticated users with moderator privileges to manipulate SQL queries by providing a malicious topic_id parameter. Exploiting this vulnerability can lead to unauthorized access, modification, or deletion of sensitive database information. The vulnerability affects versions up to 2.8.8 and poses a significant risk if a moderator account is compromised. A security patch has been released to address this issue.
Affected Version(s)
torrentpier <= 2.8.8
