A critical unauthenticated SQL injection flaw in Metabase was actively exploited as a zero-day, giving attackers administrator access to customer instances and enabling data theft from both Metabase Cloud and self-hosted deployments. Framework, Tally, and LexisNexis all reported impacts tied to the incident, with stolen data including customer contact details, login information, and in some cases password hashes. #Metabase #Framework #Tally #LexisNexis
Keypoints
- Metabase disclosed a critical zero-day SQL injection vulnerability.
- The flaw could grant unauthenticated attackers administrator access.
- Metabase Cloud and self-hosted versions were affected.
- Framework confirmed customer data was stolen from its Metabase instance.
- Tally and LexisNexis also reported incidents linked to Metabase exposure.
Read More: https://www.bleepingcomputer.com/news/security/framework-tally-disclose-metabase-data-theft-attacks/