Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2023-27163
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This vulnerability allows attackers to access network resources and sensitive information via a crafted API request.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
request-baskets 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
request-baskets是rbaskets开源的一个Web服务。 request-baskets v1.2.1版本及之前版本存在安全漏洞,该漏洞源于通过组件/api/baskets/{name}发现包含服务器端请求伪造 (SSRF)漏洞。攻击者利用该漏洞通过特制的API请求访问网络资源和敏感信息。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
-n/a n/a -
II. Public POCs for CVE-2023-27163
#POC DescriptionSource LinkShenlong Link
1Proof-of-Concept for Server Side Request Forgery (SSRF) in request-baskets (<= v.1.2.1)https://github.com/entr0pie/CVE-2023-27163POC Details
2To assist in enumerating the webserver behind the webserver SSRF CVE-2023-27163https://github.com/seanrdev/cve-2023-27163POC Details
3CVE-2023-27163https://github.com/overgrowncarrot1/CVE-2023-27163POC Details
4Poc of SSRF for Request-Baskets (CVE-2023-27163)https://github.com/ThickCoco/CVE-2023-27163-POCPOC Details
5PoC CVE-2023-27163, SSRF, request-baskets hasta v1.2.1https://github.com/davuXVI/CVE-2023-27163POC Details
6Requests Baskets (CVE-2023-27163) and Mailtrail v0.53https://github.com/HusenjanDev/CVE-2023-27163-AND-Mailtrail-v0.53POC Details
7CVE-2023-27163 - Request Baskets SSRFhttps://github.com/rvizx/CVE-2023-27163POC Details
8Golang PoC for CVE-2023-27163 Mailtrail Exploithttps://github.com/thomas-osgood/CVE-2023-27163POC Details
9CVE-2023-27163 Request-Baskets v1.2.1 - Server-side request forgery (SSRF)https://github.com/0xFTW/CVE-2023-27163POC Details
10A tool to perform port scanning using vulnerable Request-Basketshttps://github.com/samh4cks/CVE-2023-27163-InternalProberPOC Details
11Python implementation of CVE-2023-27163https://github.com/Hamibubu/CVE-2023-27163POC Details
12CVE-2023-27163 Request-Baskets v1.2.1 - Server-side request forgery (SSRF)https://github.com/cowsecurity/CVE-2023-27163POC Details
13this is a script that exploits the CVE-2023-27163 vulnerability which is request-basket SSRFhttps://github.com/KharimMchatta/basketcraftPOC Details
14Proof of Concept for Server Side Request Forgery (SSRF) in request-baskets (V<= v.1.2.1)https://github.com/MasterCode112/CVE-2023-27163POC Details
15Request Baskets vulnerable exploit to Server-Side Request Forgery up to version 1.2.1https://github.com/mathias-mrsn/CVE-2023-27163POC Details
16A exploit for the CVE-2023-27163 (SSRF) vulnerability in the web application request-baskets (<= v.1.2.1)https://github.com/Rubioo02/CVE-2023-27163POC Details
17PoC for SSRF in request-baskets v1.2.1 (CVE-2023-27163)https://github.com/madhavmehndiratta/CVE-2023-27163POC Details
18It is a simple script to automate internal port scanning dueto SSRF in requests-baskets v 1.2.1. this script can also assisst in solving 'SAU' machine from hacktheboxhttps://github.com/Rishabh-Kumar-Cyber-Sec/CVE-2023-27163-ssrf-to-port-scanningPOC Details
19Nonehttps://github.com/btar1gan/exploit_CVE-2023-27163POC Details
20SSRF CVE-2023-27163 + maltrail vuln RCEhttps://github.com/G4sp4rCS/htb-sau-automatedPOC Details
21Request Baskets is exposed.https://github.com/projectdiscovery/nuclei-templates/blob/main/http/misconfiguration/request-baskets-exposure.yamlPOC Details
22CVE-2023-27163 Request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This vulnerability allows attackers to access network resources and sensitive information via a crafted API request. This POC utilizes the SSRF to perfrom RCE.https://github.com/lukehebe/CVE-2023-27163POC Details
23Proof of Concept exploit for Server Side Request Forgery vulnerability in Requests Basket v1.2.1 and before.https://github.com/J0ey17/Exploit_CVE-2023-27163POC Details
24PoC and internal port brute-forcer for CVE-2023-27163https://github.com/theopaid/CVE-2023-27163-Request-Baskets-Local-Ports-BruteforcerPOC Details
25Request-Baskets <= 1.2.1 allows unauthenticated SSRF via the forward_url parameter when creating a new basket. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-27163.yamlPOC Details
26A exploit for the CVE-2023-27163 (SSRF) vulnerability in the web application request-baskets (<= v.1.2.1)https://github.com/apaz-dev/CVE-2023-27163POC Details
27CVE-2023-27163 Request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This vulnerability allows attackers to access network resources and sensitive information via a crafted API request. This POC utilizes the SSRF to perfrom RCE.https://github.com/lukehebe/CVE-2023-27163-POCPOC Details
28Exploit for CVE-2023-27163 - SSRF Baskets Requestshttps://github.com/thealchimist86/CVE-2023-27163---SSRF-Baskets-RequestsPOC Details
29Exploit for CVE-2023-27163 - Maltrail(0.53) - RCEhttps://github.com/thealchimist86/CVE-2023-27163---Maltrail-0.53---RCEPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2023-27163
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2023-27163

No comments yet


Leave a comment