Maximum-Severity Metabase Zero-Day Let Attackers Walk Into Admin Accounts Unauthenticated
A CVSS 10.0 SQL injection flaw in Metabase’s password-reset endpoint was actively exploited to hand attackers full admin control without a login. Metabase Cloud was breached before a patch shipped, and self-hosted instances remain at risk until upgraded.
Itagora tiene in archivio titolo e sommario per la ricerca interna. Il testo completo resta sulla fonte. Il link in uscita non invia referrer.