logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2024-32484

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2024-32484

Description:
An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04. A specially crafted flashcard can lead to JavaScript code execution and result in an arbitrary file read. An attacker can share a malicious flashcard to trigger this vulnerability.
Last updated date:
09/11/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
09/11/2024
Reference url to background

https://talosintelligence.com/vulnerability_reports/TALOS-2024-1995

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy