An issue was discovered in Ankitects Anki through 25.02. A crafted shared deck can result in attacker-controlled access to the internal API (even though the attacker has no knowledge of an API key) through approaches such as scripts or the SRC attribute of an IMG element. NOTE: this issue exists because of an incomplete fix for CVE-2024-32484.
References
Configurations
No configuration.
History
16 Apr 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-16 22:15
Updated : 2025-04-17 20:21
NVD link : CVE-2025-43703
Mitre link : CVE-2025-43703
CVE.ORG link : CVE-2025-43703
JSON object : View
Products Affected
No product.
CWE
CWE-830
Inclusion of Web Functionality from an Untrusted Source