cve/2024/CVE-2024-9765.md
2025-09-29 16:08:36 +00:00

18 lines
737 B
Markdown

### [CVE-2024-9765](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-9765)
![](https://img.shields.io/static/v1?label=Product&message=EKC%20Tournament%20Manager&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=0%3C%202.2.2%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-552%20Files%20or%20Directories%20Accessible%20to%20External%20Parties&color=brighgreen)
### Description
The EKC Tournament Manager WordPress plugin before 2.2.2 allows a logged in admin to download system files outside of the WordPress directory
### POC
#### Reference
- https://wpscan.com/vulnerability/c86157b0-43f3-4e82-9697-7dd9401b48d6/
#### Github
No PoCs found on GitHub currently.