CVE-2023-27159
HIGH EXPLOITED NUCLEIAppwrite < 1.2.1 - Server-Side Request Forgery via Avatars Favicon Endpoint
Title source: llmExploitation Summary
CVE-2023-27159 has been observed exploited in the wild (reported by VulnCheck KEV). A Nuclei detection template is also available.
Description
Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.
Nuclei Templates (1)
Appwrite <=1.2.1 - Server-Side Request Forgery
HIGHVERIFIEDby DhiyaneshDk
Shodan:
title:"Sign In - Appwrite" || http.title:"sign in - appwrite" || http.favicon.hash:-633108100
FOFA:
icon_hash=-633108100 || title="sign in - appwrite"
References (5)
Core 5
Core References
Broken Link
http://appwrite.com
Exploit, Third Party Advisory
https://gist.github.com/b33t1e/43b26c31e895baf7e7aea2dbf9743a9a
Exploit, Third Party Advisory
https://gist.github.com/b33t1e/e9e8192317c111e7897e04d2f9bf5fdb
Exploit, Third Party Advisory
https://notes.sjtu.edu.cn/gMNlpByZSDiwrl9uZyHTKA
Scores
CVSS v3
7.5
EPSS
0.3617
EPSS Percentile
98.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
VulnCheck KEV
2023-12-04
CWE
CWE-918
Status
published
Products (2)
appwrite/appwrite
< 1.2.1
appwrite/server-ce
0Packagist
Published
Mar 31, 2023
Tracked Since
Feb 18, 2026