Vulnerabilities > CVE-2024-26020 - Unspecified vulnerability in Ankiweb Anki 24.04

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
ankiweb

Summary

An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted flashcard can lead to a arbitrary code execution. An attacker can send malicious flashcard to trigger this vulnerability.

Vulnerable Configurations

Part Description Count
Application
Ankiweb
1