vendor:
Postbird
by:
Debshubra Chakraborty
5.4
CVSS
MEDIUM
Javascript Injection
79
CWE
Product Name: Postbird
Affected Version From: 2000.8.4
Affected Version To: 2000.8.4
Patch Exists: NO
Related CWE: CVE-2021-33570
CPE: a:paxa:postbird:0.8.4
Platforms Tested: Linux
2021
Postbird 0.8.4 – Javascript Injection
This exploit allows for XSS, LFI, and PostgreSQL password stealing attacks. It injects malicious JavaScript code into the Postbird application, enabling the attacker to exfiltrate data and steal credentials.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of Postbird.