Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Organization: info@thehackernews.com (The Hacker News)

Location: Global

Source: info@thehackernews.com (The Hacker News)

Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain


Apply / Read More


WhatsApp
Get Latest Updates: Join our WhatsApp Group

Scroll to Top