Armanidrisi operates a development blog platform where the observed vulnerability pattern centers on web-application input handling and access control, with recurrent issues including cross-site scripting and authorization bypass through user-controlled keys. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Armanidrisi over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-6142MEDIUM Dev blog v1.0 allows to exploit an XSS through an unrestricted file upload, together with a bad entropy of filenames. With this an attacker can upload a malicious HTML file, then g | Nov 21, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-6144MEDIUM Dev blog v1.0 allows to exploit an account takeover through the "user" cookie. With this, an attacker can access any user's session just by knowing their username.
| Nov 21, 2023 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Armanidrisi.
Media articles that mention a CVE ID that affects a product developed by Armanidrisi — matched by CVE ID, not by vendor name.