S4E just found a medium-severity finding from [ai] private ip disclosure detection scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-27159 Scanner

Detects 'Server-Side-Request-Forgery (SSRF)' vulnerability in Appwrite affects v. before 1.2.1.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.
Description

Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Sep 18, 2026View on NVD →
Detail

Appwrite is an open-source Backend as a Service (BaaS) platform that allows developers to build and manage web and mobile applications easily. It is a one-stop-shop for app developers who want to focus on the front-end of their applications without worrying about the backend. Appwrite provides various features such as user management, file storage, and authentication. It is the ideal solution for developers who want to save time and effort when building applications.

Recently, a Server-Side Request Forgery (SSRF) vulnerability was discovered in the Appwrite platform. The vulnerability, identified by the code CVE-2023-27159, was found in the component /v1/avatars/favicon. The SSRF vulnerability allows attackers to access network resources and sensitive information via a crafted GET request. This poses a significant threat to the security of not only the Appwrite platform but also the applications built with it.

When exploited, the SSRF vulnerability can lead to severe consequences for the organization and its users. Attackers can use the vulnerability to bypass security controls, access sensitive data, and execute arbitrary code on the server. They can also launch a Distributed Denial of Service (DDoS) attack, causing the service to become unavailable or slow to respond. Such attacks can result in reputational damage, financial losses, and legal repercussions for the organization.

At s4e.io, we provide a comprehensive platform to help individuals and organizations identify and mitigate vulnerabilities in their digital assets. With our advanced features, such as vulnerability scanning and continuous monitoring, you can stay ahead of potential attacks and secure your digital assets effectively. Join us today and take the first step towards a safer digital environment.

 

REFERENCES

Solution Advice

To protect against the SSRF vulnerability in Appwrite, developers can take the following precautions:

  • Keep the Appwrite platform up-to-date with the latest security patches and updates.
  • Disable unused components and services to reduce the attack surface.
  • Implement network-level security controls such as firewalls, virtual private networks (VPNs), and intrusion detection and prevention systems (IDPS).
  • Implement secure coding practices to prevent injection attacks and other vulnerabilities.
  • Conduct regular security assessments and penetration testing to identify and address security concerns proactively.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-27159 scanner - Server-Side-Request-Forgery (SSRF) vulnerability in Appwrite | S4E