Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day.

The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

Next Post

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

Related Posts
Total
0
Share