CVE-2025-64519: TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
An authenticated SQL injection vulnerability exists in the moderator control panel (modcp.php). Users with moderator permissions can exploit this vulnerability by supplying a malicious topic_id (t) parameter. This allows an authenticated moderator to execute arbitrary SQL queries, leading to the potential disclosure, modification, or deletion of any data in the database.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-64519 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →