CVE-2024-9765
EKC Tournament Manager < 2.2.2 - Local File Download Vulnerability
Record summary
CVE-2024-9765 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.
Description
The EKC Tournament Manager WordPress plugin before 2.2.2 allows a logged in admin to download system files outside of the WordPress directory
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated May 16, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
EKC Tournament ManagerDefault status: unaffected | CVE List | Before 2.2.2 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMEKC Tournament Manager WordPress plugin - Path TraversalCVSS 6.5
EKC Tournament Manager WordPress plugin < 2.2.2 contains a path traversal caused by insufficient validation, letting logged in admin users download system files outside the WordPress directory.
Impact
Logged in admin users can download arbitrary system files, potentially exposing sensitive information.
Remediation
Upgrade to version 2.2.2 or later.
Source: ProjectDiscovery