Cross-Site Scripting Vulnerability in Metabase by Metabase
CVE-2018-0697
6.1MEDIUM
What is CVE-2018-0697?
A cross-site scripting vulnerability exists in Metabase versions 0.29.3 and earlier. This flaw enables remote attackers to inject arbitrary web scripts or HTML, potentially compromising user data and session integrity. Unspecified vectors are exploited to deliver the malicious scripts, which can lead to unauthorized actions on behalf of the user or sensitive data exposure. It is crucial for users to update to the latest version to mitigate these risks.
Affected Version(s)
Metabase version 0.29.3 and earlier