Vulnerabilities and security researches forekc-tournament-manager ekc-tournament-manager
Direction: ascendingOct 25, 2024
EKC Tournament Manager # CVE-2024-49674
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 31, 2024
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in Lukas Huser EKC Tournament Manager allows Upload a Web Shell to a Web Server.This issue affects EKC Tournament Manager: from n/a through 2.2.1.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
May 19, 2025
EKC Tournament Manager # CVE-2024-9709
- CVE, Research URL
- Home page URL
- Application
- Date
- May 16, 2025
- Research Description
- The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
EKC Tournament Manager # CVE-2024-9711
- CVE, Research URL
- Home page URL
- Application
- Date
- May 16, 2025
- Research Description
- The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
EKC Tournament Manager # CVE-2024-9765
- CVE, Research URL
- Home page URL
- Application
- Date
- May 16, 2025
- Research Description
- The EKC Tournament Manager WordPress plugin before 2.2.2 allows a logged in admin to download system files outside of the WordPress directory
- Affected versions
-
Min -, max -.
- Status
-
vulnerable