cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forekc-tournament-manager ekc-tournament-manager

Direction: ascending
Oct 25, 2024

EKC Tournament Manager # CVE-2024-49674

CVE, Research URL

CVE-2024-49674

Date
Oct 31, 2024
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Lukas Huser EKC Tournament Manager allows Upload a Web Shell to a Web Server.This issue affects EKC Tournament Manager: from n/a through 2.2.1.
Affected versions
Min -, max -.
Status
vulnerable
May 19, 2025

EKC Tournament Manager # CVE-2024-9709

CVE, Research URL

CVE-2024-9709

Date
May 16, 2025
Research Description
The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Affected versions
Min -, max -.
Status
vulnerable

EKC Tournament Manager # CVE-2024-9711

CVE, Research URL

CVE-2024-9711

Date
May 16, 2025
Research Description
The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Affected versions
Min -, max -.
Status
vulnerable

EKC Tournament Manager # CVE-2024-9765

CVE, Research URL

CVE-2024-9765

Date
May 16, 2025
Research Description
The EKC Tournament Manager WordPress plugin before 2.2.2 allows a logged in admin to download system files outside of the WordPress directory
Affected versions
Min -, max -.
Status
vulnerable