Zero-Day SQL Injection Vulnerability in Metabase Cloud Exploited, Leading to Data Breaches
A zero-day SQL-injection vulnerability in Metabase Cloud versions 1.58 and above has been actively exploited, granting unauthenticated remote attackers administrator access to the application database. This flaw, which lacks a CVE identifier but carries a maximum CVSS score of 10, resulted from the application's failure to use prepared statements. Victims include n8n, which lost 136 customer records, and Kilo Code, which suffered data loss and exposure of Slack access tokens.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai