Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-27159 PoC — Appwrite 代码问题漏洞

Source
Associated Vulnerability
Title:Appwrite 代码问题漏洞 (CVE-2023-27159)
Description:Appwrite是Appwrite开源的一个端到端的后端服务器。用于打包为一组 Docker 微服务的 Web、移动、本机或后端应用程序。 Appwrite v1.2.1版本及之前版本存在安全漏洞,该漏洞源于通过组件/v1/avatars/favicon发现包含服务器端请求伪造(SSRF)漏洞。攻击者利用该漏洞通过特制的GET请求访问网络资源和敏感信息。
Description
Appwrite through 1.2.1 is susceptible to server-side request forgery via the component /v1/avatars/favicon. An attacker can potentially access network resources and sensitive information via a crafted GET request, thereby also making it possible to modify data and/or execute unauthorized administrative operations in the context of the affected site.
File Snapshot

id: CVE-2023-27159 info: name: Appwrite <=1.2.1 - Server-Side Request Forgery author: Dhiyanesh ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.