CVE-2025-43703

An issue was discovered in Ankitects Anki through 25.02. A crafted shared deck can result in attacker-controlled access to the internal API (even though the attacker has no knowledge of an API key) through approaches such as scripts or the SRC attribute of an IMG element. NOTE: this issue exists because of an incomplete fix for CVE-2024-32484.
Configurations

No configuration.

History

16 Apr 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-16 22:15

Updated : 2025-04-17 20:21


NVD link : CVE-2025-43703

Mitre link : CVE-2025-43703

CVE.ORG link : CVE-2025-43703


JSON object : View

Products Affected

No product.

CWE
CWE-830

Inclusion of Web Functionality from an Untrusted Source