Upload Web Shell Vulnerability Affects EKC Tournament Manager
CVE-2024-49674

9.6CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
31 October 2024

What is CVE-2024-49674?

A Cross-Site Request Forgery (CSRF) vulnerability exists in EKC Tournament Manager developed by Lukas Huser, which permits an attacker to upload a web shell to the server. This can lead to complete control over the affected system, allowing the attacker to execute arbitrary commands. The issue affects versions from n/a through 2.2.1, making it imperative for users to review their installation and apply security measures to mitigate potential exploitation.

Affected Version(s)

EKC Tournament Manager 0 <= 2.2.1

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.