Cross-Site Request Forgery (CSRF) vulnerability in lukashuser EKC Tournament Manager ekc-tournament-manager allows Upload a Web Shell to a Web Server.This issue affects EKC Tournament Manager: from n/a through <= 2.2.1.CreditsJoshua Chan | Patchstack Bug Bounty ProgramReferenceshttps://patchstack.com/database/Wordpress/Plugin/ekc-tournament-manager/vulnerability/wordpress-ekc-tournament-manager-plugin-2-2-1-csrf-to-arbitrary-file-upload-vulnerability?_s_id=cve