Record summary

CVE-2023-27159 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 4, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 18, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
GitHub AdvisoryThrough 1.2.1affected

Nuclei templates

1
ProjectDiscoveryHIGHAppwrite <=1.2.1 - Server-Side Request ForgeryCVSS 7.5

Appwrite through 1.2.1 is susceptible to server-side request forgery via the component /v1/avatars/favicon. An attacker can potentially access network resources and sensitive information via a crafted GET request, thereby also making it possible to modify data and/or execute unauthorized administrative operations in the context of the affected site.

Impact

This vulnerability can lead to unauthorized access to internal resources, potential data leakage, and further exploitation of the server.

Remediation

Upgrade Appwrite to a version higher than 1.2.1 to mitigate the SSRF vulnerability.

WeaknessesCWE-918
AuthorsDhiyaneshDk
Template tagscve2023cveappwritessrfoastvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:appwrite:appwrite:*:*:*:*:*:*:*:*
Shodan: title:"Sign In - Appwrite"
Shodan: http.title:"sign in - appwrite"
Shodan: http.favicon.hash:-633108100
FOFA: icon_hash=-633108100
FOFA: title="sign in - appwrite"
Google: intitle:"sign in - appwrite"

Source: ProjectDiscovery

References

6