Vulnerabilities > CVE-2024-32152 - Unspecified vulnerability in Ankitects Anki 24.04

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE
network
low complexity
ankitects

Summary

A blocklist bypass vulnerability exists in the LaTeX functionality of Ankitects Anki 24.04. A specially crafted malicious flashcard can lead to an arbitrary file creation at a fixed path. An attacker can share a malicious flashcard to trigger this vulnerability.

Vulnerable Configurations

Part Description Count
Application
Ankitects
1
OS
Linux
1
OS
Microsoft
1