2025-09-29 16:08:36 +00:00
|
|
|
### [CVE-2024-9765](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-9765)
|
|
|
|
|

|
2025-09-29 21:09:30 +02:00
|
|
|

|
|
|
|
|

|
2025-09-29 16:08:36 +00:00
|
|
|
|
|
|
|
|
### Description
|
|
|
|
|
|
|
|
|
|
The EKC Tournament Manager WordPress plugin before 2.2.2 allows a logged in admin to download system files outside of the WordPress directory
|
|
|
|
|
|
|
|
|
|
### POC
|
|
|
|
|
|
|
|
|
|
#### Reference
|
|
|
|
|
- https://wpscan.com/vulnerability/c86157b0-43f3-4e82-9697-7dd9401b48d6/
|
|
|
|
|
|
|
|
|
|
#### Github
|
|
|
|
|
No PoCs found on GitHub currently.
|
|
|
|
|
|