
Security·
Metabase's password-reset endpoint handed out admin, and Framework had to email every customer
A CVSS 10.0 SQL injection in Metabase was exploited from August 3. Framework told every customer their data was taken. Tally lost emails and password hashes.