CVE-2014-6028: Torrentflux Project Torrentflux
Medium severity, CVSS 4.0. EPSS: 1.7% chance of exploitation in the next 30 days.
TorrentFlux 2.4 allows remote authenticated users to obtain other users' cookies via the cid parameter in an editCookies action to profile.php.
Affected products
- Torrentflux Project Torrentflux: version 2.4 only
Published 2014-09-05. Last modified 2026-06-17.