Impact
Metabase allows an unauthenticated attacker to inject arbitrary SQL through a publicly shared card or dashboard that exposes a field-filter (dimension) parameter. The injection can execute any SQL statement against the database, enabling data disclosure, modification, or destruction of data. This weakness aligns with CWE-89, which represents untrusted input influencing the generation of SQL statements.
Affected Systems
Metabase is the affected vendor and product. No specific version information is provided in the CVE data; the vulnerability applies to any Metabase deployment that permits publicly shared cards or dashboards exposing a field-filter dimension parameter.
Risk and Exploitability
The CVSS score of 10 denotes critical severity, and the vulnerability is exploitable by any unauthenticated user who obtains a link to a shared card or dashboard. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Because the attack vector is a web-based shared resource accessible to anyone with the link, exploitation is likely if the shared resource is widely exposed.
OpenCVE Enrichment