CVE-2023-27159

HIGH EXPLOITED NUCLEI

Appwrite <1.2.1 - SSRF

Title source: llm

Description

Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.

Nuclei Templates (1)

Appwrite <=1.2.1 - Server-Side Request Forgery
HIGHVERIFIEDby DhiyaneshDk
Shodan: title:"Sign In - Appwrite" || http.title:"sign in - appwrite" || http.favicon.hash:-633108100
FOFA: icon_hash=-633108100 || title="sign in - appwrite"

Scores

CVSS v3 7.5
EPSS 0.8025
EPSS Percentile 99.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

VulnCheck KEV 2023-12-04
CWE
CWE-918
Status published
Products (2)
appwrite/appwrite < 1.2.1
appwrite/server-ce 0Packagist
Published Mar 31, 2023
Tracked Since Feb 18, 2026