An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted flashcard can lead to a arbitrary code execution. An attacker can send malicious flashcard to trigger this vulnerability.
Metrics
Affected Vendors & Products
References
History
Wed, 11 Sep 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ankiweb
Ankiweb anki |
|
CPEs | cpe:2.3:a:ankiweb:anki:24.04:*:*:*:*:*:*:* | |
Vendors & Products |
Ankiweb
Ankiweb anki |
MITRE
Status: PUBLISHED
Assigner: talos
Published: 2024-07-22T14:20:26.617Z
Updated: 2024-08-01T23:59:31.072Z
Reserved: 2024-05-06T16:38:51.434Z
Link: CVE-2024-26020
Vulnrichment
Updated: 2024-07-22T18:23:45.709Z
NVD
Status : Modified
Published: 2024-07-22T15:15:02.660
Modified: 2024-11-21T09:01:46.630
Link: CVE-2024-26020
Redhat
No data.