Attackers chained SQL injection with Oracle’s embedded Java capabilities to hide a custom post-exploitation toolkit inside the database and gain SYSTEM-level access to the underlying Windows server.
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. Hackers exploited a SQL ...
A single unauthenticated HTTP request to Metabase's password-reset endpoint was all it took for an attacker to gain full administrator access to an analytics platform trusted by tens of thousands of ...
Someone managed to pair the classic SQL Injection (SQLi) attack with a nifty database trick to take over the underlying system entirely. Security researchers Huntress, who were called in to ...