VendorsAnkitectsanki24.04
Vulnerabilities

Ankitects Anki 24.04

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2024-32484
An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04. A specially crafted flashcard can lead to JavaScript code execution and result in an arbitrary file read. An attacker can share a malicious flashcard to trigger this vulnerability.
Published 2024-07-22 · Modified
8.2EPSS 0.223
CVE-2024-32152
A blocklist bypass vulnerability exists in the LaTeX functionality of Ankitects Anki 24.04. A specially crafted malicious flashcard can lead to an arbitrary file creation at a fixed path. An attacker can share a malicious flashcard to trigger this vulnerability.
Published 2024-07-22 · Modified
4.3EPSS 0.127