metabase-installer-exposure: Metabase Installer - Exposure

日期: 2025-12-12 | 影响软件: Metabase Installer | POC: 已公开

漏洞描述

Detected Metabase installer page, allowing unauthorized database setup and configuration.

PoC代码[已公开]

id: metabase-installer-exposure

info:
  name: Metabase Installer - Exposure
  author: 0x_Akoko
  severity: high
  description: |
    Detected Metabase installer page, allowing unauthorized database setup and configuration.
  reference:
    - https://www.metabase.com/docs/latest/installation-and-operation/installing-metabase
  metadata:
    verified: true
    max-request: 1
    shodan-query: http.title:"Metabase" http.html:"setup"
    fofa-query: title="Metabase" && body="setup"
    google-dork: intitle:"Metabase" "Let's get started"
  tags: exposure,metabase,installer,misconfig,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/setup"

    matchers-condition: and
    matchers:
      - type: dsl
        dsl:
          - 'status_code == 200'
          - 'contains(to_lower(body), "<title>metabase</title>")'
          - 'contains_all(body, "\"has-user-setup\":false", "_metabaseBootstrap")'
        condition: and
# digest: 4a0a004730450220604f6d8d390c6b858ec40ab3d457e2940889d471ad85ca593a31f8e2d32e35e6022100837ce6bb307ccb4dcda6b57466a77ffb7a40cebe82568efffef5bf40455ff46d:922c64590222798bb761d5b6d8e72950

相关漏洞推荐