← back
CVE-2023-27159highobserved exploitationCWE-918

CVE-2023-27159

70Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 7.5epss 36%
from disclosure to weapon
Published on NVDMar 31
VulnCheck+248d
exploitation probability
36%top 2% of all CVEs
observed exploitation
yesVulnCheck
Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
n/a · n/a