TL;DR what: Metabase disclosed that an unauthenticated SQL injection flaw in its BI platform was exploited in the wild as a zero-day, letting remote attackers write to the application database and grant themselves administrator access. Metabase is telling self-hosted customers to patch now. An ...

Source: [Dev.to](https://dev.to/etairos/metabase-zero-day-hits-cvss-100-unauthenticated-sql-injection-gives-full-admin-1fi9)

Sponsored