CVE-2021-33570
Dashboard / Vulnerabilities / CVE-2021-33570
CVE-2021-33570
Summary:
Details: Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can result in reading local files via vectors involving XMLHttpRequest and open of a file:/// URL, or discovering PostgreSQL passwords via vectors involving Window.localStorage and savedConnections.
References: http://packetstormsecurity.com/files/162872/Postbird-0.8.4-XSS-LFI-Insecure-Data-Storage.html, https://tridentsec.io/blogs/postbird-cve-2021-33570/, https://github.com/Paxa/postbird/issues/132, https://github.com/Paxa/postbird/issues/133, https://github.com/Paxa/postbird/issues/134, http://packetstormsecurity.com/files/162831/Postbird-0.8.4-Cross-Site-Scripting-Local-File-Inclusion.html, https://github.com/Tridentsec-io/postbird, https://www.exploit-db.com/exploits/49910
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
