Medium severity5.4NVD Advisory· Published May 25, 2021· Updated Jun 17, 2026
CVE-2021-33570
CVE-2021-33570
Description
Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can result in reading local files via vectors involving XMLHttpRequest and open of a file:/// URL, or discovering PostgreSQL passwords via vectors involving Window.localStorage and savedConnections.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:postbird_project:postbird:0.8.4:*:*:*:*:*:*:*
- Postbird/Postbirddescription
Patches
Vulnerability mechanics
References
7- packetstormsecurity.com/files/162831/Postbird-0.8.4-Cross-Site-Scripting-Local-File-Inclusion.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.exploit-db.com/exploits/49910nvdExploitThird Party AdvisoryVDB Entry
- packetstormsecurity.com/files/162872/Postbird-0.8.4-XSS-LFI-Insecure-Data-Storage.htmlnvdThird Party AdvisoryVDB Entry
- github.com/Paxa/postbird/issues/132nvdIssue TrackingThird Party Advisory
- github.com/Paxa/postbird/issues/133nvdIssue TrackingThird Party Advisory
- github.com/Paxa/postbird/issues/134nvdIssue TrackingThird Party Advisory
- tridentsec.io/blogs/postbird-cve-2021-33570/nvdBroken LinkThird Party AdvisoryURL Repurposed
News mentions
0No linked articles in our index yet.