A password-reset endpoint with a CVSS 10.0 score let attackers become Metabase admins with zero credentials — and Framework's customers paid for it.
The short version
The short version
The short version
The short version
The short version
My honest take
Aliteq
framework just told every customer their data leaked — the bug was a password reset box