SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  Metabase reset_password SQL Injection

Category: WEB-ATTACKS      

This is a CRITICAL vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data. Metabase has confirmed active exploitation of this vulnerability.


Relevant Information