CVE-2023-27159
appwrite
Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.
- CVSS
- 7.5
- EPSS
- 36.2% 98.3% percentile
- CISA KEV
- Not listed
- Published
- 2023.04.01