Hosted on MSN
Metabase SQL injection breached five companies, exposed all connected database credentials
A single unauthenticated HTTP request to Metabase's password-reset endpoint was all it took for an attacker to gain full administrator access to an analytics platform trusted by tens of thousands of ...
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft ...
A zero-day SQL-injection vulnerability in Metabase Cloud is under exploitation in the wild, and it could spell trouble for many downstream organizations. Metabase, which provides AI-driven business ...
Metabase says a CVSS 10.0 zero-day SQL injection was exploited in the wild; the flaw can grant admin access and expose ...
A critical-severity SQL injection vulnerability in Metabase has been exploited as a zero-day to gain administrative privileges.
Spread the loveImagine waking up to discover that the very tool you rely on for critical business insights, the one that ...
The critical zero-day can provide direct SQL access to Metabase’s underlying database, potentially exposing credentials, API keys, and other sensitive data.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results