← Back

CVE-2025-43703

nvd nist
Published: Apr 16, 2025Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.5
Source: NVD

Description

An issue was discovered in Ankitects Anki through 25.02. A crafted shared deck can result in attacker-controlled access to the internal API (even though the attacker has no knowledge of an API key) through approaches such as scripts or the SRC attribute of an IMG element. NOTE: this issue exists because of an incomplete fix for CVE-2024-32484.

Affected (1)

Products: Ankitects: Anki
1 product
Anki
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 25.02

Timeline

No history available yet.