CVE-2023-27159

HIGH EXPLOITED NUCLEI

Appwrite < 1.2.1 - Server-Side Request Forgery via Avatars Favicon Endpoint

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2023-27159 has been observed exploited in the wild (reported by VulnCheck KEV). A Nuclei detection template is also available.

Description

Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.

Nuclei Templates (1)

Appwrite <=1.2.1 - Server-Side Request Forgery
HIGHVERIFIEDby DhiyaneshDk
Shodan: title:"Sign In - Appwrite" || http.title:"sign in - appwrite" || http.favicon.hash:-633108100
FOFA: icon_hash=-633108100 || title="sign in - appwrite"

References (5)

Core 5

Scores

CVSS v3 7.5
EPSS 0.3617
EPSS Percentile 98.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

VulnCheck KEV 2023-12-04
CWE
CWE-918
Status published
Products (2)
appwrite/appwrite < 1.2.1
appwrite/server-ce 0Packagist
Published Mar 31, 2023
Tracked Since Feb 18, 2026