SECURITYTHE HACKER NEWS
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Metabase warned that a maximum-severity security flaw in its business intelligence and data visualization software has been exploited as a zero-day. The vulnerability, which has a CVSS score of 10.0, allows an unauthenticated remote attacker to inject arbitrary SQL into the application database. This capability could enable attackers to gain admin access without authentication.
Mentioned
Related Signal
Adjacent reporting
- Bug of the year (so far): Nasty cPanel vulnerability probably exploited as a 0-day
- Microsoft Exchange Zero-Day Under Attack, No Patch Available
- A critical Palo Alto PAN-OS zero-day is being exploited in the wild
- Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
- Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges