Back to search
CVE-2021-33570
Published: May 25, 2021
Modified: Aug 3, 2024
PUBLISHED
Description
Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can result in reading local files via vectors involving XMLHttpRequest and open of a file:/// URL, or discovering PostgreSQL passwords via vectors involving Window.localStorage and savedConnections.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://github.com/Paxa/postbird/issues/132
x_refsource_MISC
https://github.com/Paxa/postbird/issues/133
x_refsource_MISC
https://github.com/Paxa/postbird/issues/134
x_refsource_MISC
https://github.com/Tridentsec-io/postbird
x_refsource_MISC
https://www.exploit-db.com/exploits/49910
x_refsource_MISC
https://tridentsec.io/blogs/postbird-cve-2021-33570/
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now