cve/2024/CVE-2024-32484.md
2024-07-25 21:25:12 +00:00

863 B

CVE-2024-32484

Description

An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04. A specially crafted flashcard can lead to JavaScript code execution and result in an arbitrary file read. An attacker can share a malicious flashcard to trigger this vulnerability.

POC

Reference

No PoCs from references.

Github