๐จ ACTIVE EXPLOITATION
- Metabase SQL Injection Zero-Day Exploited to Steal Customer Data UPDATE:
Attackers exploited a Metabase SQL injection zero-day to access customer data.
- Metabase Cloud and self-hosted deployments on the 0.58โ0.63 branches were affected.
- The critical GHSA-vwf4-m7j8-wcjf flaw was an unauthenticated SQL injection vulnerability with a CVSS score of 10.0.
- Successful exploitation could grant administrator access and expose connected-database credentials and data.
- Framework and Tally confirmed unauthorized access to customer information, including contact details and password hashes.
- The attack used POST /api/session/reset_password returning 400, followed by GET /api/user/current returning 200. ๐ Source: github.com ยท ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News