CVE-2025-43703
An issue was discovered in Ankitects Anki through 25.02. A crafted shared deck can result in attacker-controlled access to the internal API (even though the attacker has no knowledge of an API key) through approaches such as scripts or the SRC attribute of an IMG element. NOTE: this issue exists because of an incomplete fix for CVE-2024-32484.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS probability
- 0.22%
- CWE
- CWE-830
- Published
- 2025-04-16
- Last modified
- 2026-03-13
Affected products
- Ankitects Anki
Weakness type
Related vulnerabilities
- CVE-2025-65109 — Minder does not sandbox http.send in Rego programs
- CVE-2025-64496 — Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
- CVE-2025-46652 — In IZArc through 4.5, there is a Mark-of-the-Web Bypass Vulnerability. When a user performs an...
- CVE-2025-33028 — In WinZip through 29.0, there is a Mark-of-the-Web Bypass Vulnerability because of an incomplete...
- CVE-2025-33027 — In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability. This...
- CVE-2025-33026 — In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability...
- CVE-2024-35180 — OMERO.web JSONP callback vulnerability
- CVE-2023-2588