Description
Acunetix determined that it was possible to access Metabase's sensitive files without authentication.
Remediation
Upgrade to the latest version of Metabase
References
Related Vulnerabilities
WordPress 3.0.4 Multiple Vulnerabilities (0.6.2 - 3.0.4)
PHP allow_url_include Is Enabled
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-7983)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2158)
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-6514)