packetstormsecurity.com
http://packetstormsecurity.com/files/162831/Postbird-0.8.4-Cross-Site-Scripting-Local-File-Inclusion.html CVE-2021-33570
MEDIUM
Postbird 0.8.4 - Javascript Injection
Record summary
CVE-2021-33570 has a selected CVSS score of 5.4 (medium); EIP currently links 1 catalogued exploit.
Description
Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can result in reading local files via vectors involving XMLHttpRequest and open of a file:/// URL, or discovering PostgreSQL passwords via vectors involving Window.localStorage and savedConnections.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPostbird 0.8.4 - Javascript InjectionExploitDB exploitby Debshubra ChakrabortyNot analyzed1 file
References
9packetstormsecurity.com
http://packetstormsecurity.com/files/162872/Postbird-0.8.4-XSS-LFI-Insecure-Data-Storage.html github.com
https://github.com/Paxa/postbird/issues/132 github.com
https://github.com/Paxa/postbird/issues/133 github.com
https://github.com/Paxa/postbird/issues/134 github.com
https://github.com/Tridentsec-io/postbird nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-33570 tridentsec.io
https://tridentsec.io/blogs/postbird-cve-2021-33570 exploit-db.com
https://www.exploit-db.com/exploits/49910