CVE-2021-33570 EXPLOIT
5.4
MEDIUM · CVSS 3.1 · EPSS 3.6% (pctl 89)
Patch early
A public exploit exists.
Description
Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can result in reading local files via vectors involving XMLHttpRequest and open of a file:/// URL, or discovering PostgreSQL passwords via vectors involving Window.localStorage and savedConnections.
Scoring
| CVSS | 5.4 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
| EPSS | 3.56% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2021-05-25 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| postbird project | postbird |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Postbird 0.8.4 - Javascript Injection | 2021-05-27 |
References
- http://packetstormsecurity.com/files/162831/Postbird-0.8.4-Cross-Site-Scripting-Local-File-Inclusion.html
- http://packetstormsecurity.com/files/162872/Postbird-0.8.4-XSS-LFI-Insecure-Data-Storage.html
- https://github.com/Paxa/postbird/issues/132
- https://github.com/Paxa/postbird/issues/133
- https://github.com/Paxa/postbird/issues/134
- https://github.com/Tridentsec-io/postbird
- https://tridentsec.io/blogs/postbird-cve-2021-33570/
- https://www.exploit-db.com/exploits/49910
- http://packetstormsecurity.com/files/162831/Postbird-0.8.4-Cross-Site-Scripting-Local-File-Inclusion.html
- http://packetstormsecurity.com/files/162872/Postbird-0.8.4-XSS-LFI-Insecure-Data-Storage.html
- https://github.com/Paxa/postbird/issues/132
- https://github.com/Paxa/postbird/issues/133
- https://github.com/Paxa/postbird/issues/134
- https://github.com/Tridentsec-io/postbird
- https://tridentsec.io/blogs/postbird-cve-2021-33570/
- https://www.exploit-db.com/exploits/49910
→ the Explorer · watch your stack · NVD