Cross-Site Scripting Vulnerability in Metabase by Metabase
CVE-2018-0697

6.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
15 November 2018

What is CVE-2018-0697?

A cross-site scripting vulnerability exists in Metabase versions 0.29.3 and earlier. This flaw enables remote attackers to inject arbitrary web scripts or HTML, potentially compromising user data and session integrity. Unspecified vectors are exploited to deliver the malicious scripts, which can lead to unauthorized actions on behalf of the user or sensitive data exposure. It is crucial for users to update to the latest version to mitigate these risks.

Affected Version(s)

Metabase version 0.29.3 and earlier

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.