5.4
CVE-2024-9709
- EPSS 0.04%
- Veröffentlicht 15.05.2025 20:16:01
- Zuletzt bearbeitet 28.05.2025 15:41:13
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
EKC Tournament Manager <= 2.2.1 - Cross-Site Request Forgery to Tournament and Team Creation
The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Mögliche Gegenmaßnahme
EKC Tournament Manager: Update to version 2.2.2, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
EKC Tournament Manager
Version
*-2.2.1
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lukashuser ≫ Ekc Tournament Manager SwPlatformwordpress Version < 2.2.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.117 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.