CVE-2023-27163

MEDIUM EXPLOITED NUCLEI

request-baskets <1.2.1 - SSRF

Title source: llm

Description

request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This vulnerability allows attackers to access network resources and sensitive information via a crafted API request.

Exploits (30)

nomisec WORKING POC 30 stars
by entr0pie · remote
https://github.com/entr0pie/CVE-2023-27163
nomisec WORKING POC 5 stars
by samh4cks · infoleak
https://github.com/samh4cks/CVE-2023-27163-InternalProber
nomisec WORKING POC 4 stars
by seanrdev · infoleak
https://github.com/seanrdev/cve-2023-27163
nomisec WORKING POC 2 stars
by MasterCode112 · infoleak
https://github.com/MasterCode112/CVE-2023-27163
nomisec WORKING POC 2 stars
by apaz-dev · poc
https://github.com/apaz-dev/CVE-2023-27163
nomisec WORKING POC 2 stars
by thomas-osgood · infoleak
https://github.com/thomas-osgood/CVE-2023-27163
nomisec WORKING POC 2 stars
by rvizx · infoleak
https://github.com/rvizx/CVE-2023-27163
nomisec WORKING POC 2 stars
by HusenjanDev · client-side
https://github.com/HusenjanDev/CVE-2023-27163-AND-Mailtrail-v0.53
nomisec WORKING POC 1 stars
by theopaid · poc
https://github.com/theopaid/CVE-2023-27163-Request-Baskets-Local-Ports-Bruteforcer
nomisec WORKING POC 1 stars
by J0ey17 · infoleak
https://github.com/J0ey17/Exploit_CVE-2023-27163
nomisec WORKING POC 1 stars
by KharimMchatta · infoleak
https://github.com/KharimMchatta/basketcraft
nomisec WORKING POC 1 stars
by davuXVI · client-side
https://github.com/davuXVI/CVE-2023-27163
nomisec WORKING POC 1 stars
by ThickCoco · client-side
https://github.com/ThickCoco/CVE-2023-27163-POC
nomisec WORKING POC
by tombstoneghost · remote
https://github.com/tombstoneghost/htb-sau-exploit-chain
nomisec WORKING POC
by thealchimist86 · poc
https://github.com/thealchimist86/CVE-2023-27163---Maltrail-0.53---RCE
nomisec WORKING POC
by thealchimist86 · infoleak
https://github.com/thealchimist86/CVE-2023-27163---SSRF-Baskets-Requests
nomisec WORKING POC
by lukehebe · poc
https://github.com/lukehebe/CVE-2023-27163-POC
nomisec WORKING POC
by G4sp4rCS · remote
https://github.com/G4sp4rCS/htb-sau-automated
nomisec NO CODE
by btar1gan · poc
https://github.com/btar1gan/exploit_CVE-2023-27163
github WORKING POC
by dugisan3rd · pythonpoc
https://github.com/dugisan3rd/exploit/tree/main/'request-baskets'-SSRF (CVE-2023-27163)
nomisec WORKING POC
by Rishabh-Kumar-Cyber-Sec · remote-auth
https://github.com/Rishabh-Kumar-Cyber-Sec/CVE-2023-27163-ssrf-to-port-scanning
nomisec WORKING POC
by madhavmehndiratta · infoleak
https://github.com/madhavmehndiratta/CVE-2023-27163
nomisec WORKING POC
by Hamibubu · infoleak
https://github.com/Hamibubu/CVE-2023-27163
nomisec WORKING POC
by cowsecurity · poc
https://github.com/cowsecurity/CVE-2023-27163
nomisec WORKING POC
by overgrowncarrot1 · infoleak
https://github.com/overgrowncarrot1/CVE-2023-27163
vulncheck_xdb WORKING POC
infoleak
https://github.com/theopaid/CVE-2023-27163-Request-Baskets
vulncheck_xdb WORKING POC
infoleak
https://github.com/lukehebe/CVE-2023-27163
vulncheck_xdb WORKING POC
remote
https://github.com/Rubioo02/CVE-2023-27163
vulncheck_xdb WORKING POC
infoleak
https://github.com/mathias-mrsn/CVE-2023-27163
vulncheck_xdb WORKING POC
remote
https://github.com/josephberger/CVE-2023-27163

Nuclei Templates (1)

Request-Baskets <= 1.2.1 - Server Side Request Forgery
MEDIUMVERIFIEDby Jaenact
Shodan: http.html:"Request-Baskets"
FOFA: body="Request-Baskets"

Scores

CVSS v3 6.5
EPSS 0.9332
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Details

VulnCheck KEV 2025-10-13
CWE
CWE-918
Status published
Products (2)
darklynx/request-baskets 0Go
rbaskets/request_baskets < 1.2.1
Published Mar 31, 2023
Tracked Since Feb 18, 2026