0-day SQL Injection in Metabase, no CVE assigned yet, 10.0 rating 🔥🔥🔥
Recently disclosed vulnerability in Metabase allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. This vulnerability is already being actively exploited in the wild!
Search at Netlas.io:
👉 Link: https://nt.ls/q4U1I
👉 Dork: http.favicon.hash_sha256:61c0353e2bde23f74f7febc277df979fbc1017186de060fd9bd8d07b65bcac13 OR http.headers.set_cookie:"metabase.DEVICE" OR http.title:"Metabase"
Vendor's advisory:
https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf
Post #609
513

- 🔥 4
- ❤ 2
- 👍 2