CVE-2021-33570
MEDIUMPostbird 0.8.4 - Stored Cross-Site Scripting via IMG onerror Attribute
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-33570. PoCs published by Debshubra Chakraborty.
AI-analyzed exploit summary This exploit demonstrates a JavaScript injection vulnerability in Postbird 0.8.4, allowing XSS, LFI, and credential theft via crafted payloads. It includes a Python server to exfiltrate data from the victim's machine.
Description
Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can result in reading local files via vectors involving XMLHttpRequest and open of a file:/// URL, or discovering PostgreSQL passwords via vectors involving Window.localStorage and savedConnections.
Exploits (1)
This exploit demonstrates a JavaScript injection vulnerability in Postbird 0.8.4, allowing XSS, LFI, and credential theft via crafted payloads. It includes a Python server to exfiltrate data from the victim's machine.
References (8)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N