Vulnerabilities > CVE-2024-29073 - Inclusion of Functionality from Untrusted Control Sphere vulnerability in Ankiweb Anki 24.04

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
ankiweb
CWE-829

Summary

An vulnerability in the handling of Latex exists in Ankitects Anki 24.04. When Latex is sanitized to prevent unsafe commands, the verbatim package, which comes installed by default in many Latex distributions, has been overlooked. A specially crafted flashcard can lead to an arbitrary file read. An attacker can share a flashcard to trigger this vulnerability.

Vulnerable Configurations

Part Description Count
Application
Ankiweb
1