Логотип exploitDog
bind:CVE-2021-33570
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-33570

Количество 2

Количество 2

nvd логотип

CVE-2021-33570

больше 4 лет назад

Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can result in reading local files via vectors involving XMLHttpRequest and open of a file:/// URL, or discovering PostgreSQL passwords via vectors involving Window.localStorage and savedConnections.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-38qm-8h84-7h9v

больше 3 лет назад

Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can result in reading local files via vectors involving XMLHttpRequest and open of a file:/// URL, or discovering PostgreSQL passwords via vectors involving Window.localStorage and savedConnections.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-33570

Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can result in reading local files via vectors involving XMLHttpRequest and open of a file:/// URL, or discovering PostgreSQL passwords via vectors involving Window.localStorage and savedConnections.

CVSS3: 5.4
2%
Низкий
больше 4 лет назад
github логотип
GHSA-38qm-8h84-7h9v

Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can result in reading local files via vectors involving XMLHttpRequest and open of a file:/// URL, or discovering PostgreSQL passwords via vectors involving Window.localStorage and savedConnections.

CVSS3: 5.4
2%
Низкий
больше 3 лет назад

Уязвимостей на страницу