CVE-2025-64519
PHP vulnerability analysis and mitigation

Overview

TorrentPier, an open source BitTorrent Public/Private tracker engine written in PHP, contains an authenticated SQL injection vulnerability (CVE-2025-64519) in versions up to and including 2.8.8. The vulnerability exists in the moderator control panel (modcp.php) where authenticated users with moderator permissions can exploit the vulnerability through the topic_id (t) parameter. The issue was discovered and disclosed in November 2025 (GitHub Advisory).

Technical details

The vulnerability occurs in the moderator control panel when processing requests that include a topicid parameter. The $topicid value is taken directly from user input without proper sanitization or parameterization before being concatenated into SQL queries. This vulnerability has been assigned a CVSS v3.1 base score of 8.8 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The issue is classified as CWE-89 (SQL Injection) (GitHub Advisory, NVD).

Impact

Despite requiring moderator privileges, the vulnerability is considered severe as it allows authenticated moderators to execute arbitrary SQL queries. This can lead to unauthorized access to sensitive data, including user credentials, private messages, and email addresses. Additionally, attackers can modify or delete database records, potentially corrupting forum data or elevating privileges (GitHub Advisory).

Mitigation and workarounds

A patch has been released in commit 6a0f6499d89fa5d6e2afa8ee53802a1ad11ece80 which implements proper input validation by casting the topic_id parameter to an integer. Organizations running affected versions should update their installations immediately (GitHub Commit).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-64519HIGH8.8
  • PHPPHP
  • torrentpier/torrentpier
NoNoNov 10, 2025
CVE-2025-64500HIGH7.3
  • PHPPHP
  • symfony/symfony
NoYesNov 12, 2025
CVE-2025-55155MEDIUM5.4
  • PHPPHP
  • mantisbt/mantisbt
NoYesNov 04, 2025
CVE-2025-62520MEDIUM5.3
  • PHPPHP
  • mantisbt/mantisbt
NoYesNov 04, 2025
CVE-2025-64174MEDIUM4.6
  • PHPPHP
  • openmage/magento-lts
NoYesNov 06, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management