Upload Web Shell Vulnerability Affects EKC Tournament Manager
CVE-2024-49674
9.6CRITICAL
What is CVE-2024-49674?
A Cross-Site Request Forgery (CSRF) vulnerability exists in EKC Tournament Manager developed by Lukas Huser, which permits an attacker to upload a web shell to the server. This can lead to complete control over the affected system, allowing the attacker to execute arbitrary commands. The issue affects versions from n/a through 2.2.1, making it imperative for users to review their installation and apply security measures to mitigate potential exploitation.
Affected Version(s)
EKC Tournament Manager 0 <= 2.2.1