CVE-2023-27159
HIGH EXPLOITED NUCLEIAppwrite <1.2.1 - SSRF
Title source: llmDescription
Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.
Nuclei Templates (1)
Appwrite <=1.2.1 - Server-Side Request Forgery
HIGHVERIFIEDby DhiyaneshDk
Shodan:
title:"Sign In - Appwrite" || http.title:"sign in - appwrite" || http.favicon.hash:-633108100
FOFA:
icon_hash=-633108100 || title="sign in - appwrite"
References (5)
Scores
CVSS v3
7.5
EPSS
0.8025
EPSS Percentile
99.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
VulnCheck KEV
2023-12-04
CWE
CWE-918
Status
published
Products (2)
appwrite/appwrite
< 1.2.1
appwrite/server-ce
0Packagist
Published
Mar 31, 2023
Tracked Since
Feb 18, 2026