Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r6f4-5657-3fp7

Опубликовано: 22 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.4

Описание

An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04. A specially crafted flashcard can lead to JavaScript code execution and result in an arbitrary file read. An attacker can share a malicious flashcard to trigger this vulnerability.

An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04. A specially crafted flashcard can lead to JavaScript code execution and result in an arbitrary file read. An attacker can share a malicious flashcard to trigger this vulnerability.

EPSS

Процентиль: 90%
0.05963
Низкий

7.4 High

CVSS3

Дефекты

CWE-80

Связанные уязвимости

CVSS3: 7.4
ubuntu
больше 1 года назад

An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04. A specially crafted flashcard can lead to JavaScript code execution and result in an arbitrary file read. An attacker can share a malicious flashcard to trigger this vulnerability.

CVSS3: 7.4
nvd
больше 1 года назад

An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04. A specially crafted flashcard can lead to JavaScript code execution and result in an arbitrary file read. An attacker can share a malicious flashcard to trigger this vulnerability.

CVSS3: 7.4
debian
больше 1 года назад

An reflected XSS vulnerability exists in the handling of invalid paths ...

EPSS

Процентиль: 90%
0.05963
Низкий

7.4 High

CVSS3

Дефекты

CWE-80