CRITICAL: Metabase CVSS 10.0 Zero-Day Exploited to Breach Framework and Tally
Metabase disclosed a CVSS 10.0 unauthenticated SQL injection flaw that was already being exploited as a zero-day, handing attackers administrator access and every stored database credential. Framework, Tally, and LexisNexis have all been named. No CVE was assigned, so scanners will not flag it.