id: metabase-panel info: name: Metabase Login Panel - Detect author: revblock,daffainfo severity: info description: Metabase login panel was detected. classification: cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N cwe-id: CWE-200 cpe: cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:* metadata: max-request: 1 vendor: metabase product: metabase shodan-query: - http.title:"Metabase" - http.title:"metabase" fofa-query: - title="metabase" - app="metabase" google-query: intitle:"metabase" tags: panel,metabase,login http: - method: GET path: - "{{BaseURL}}/auth/login" matchers-condition: and matchers: - type: status status: - 200 - type: word part: body words: - "Metabase" - "window.MetabaseBootstrap" - "window.MetabaseRoot" condition: and extractors: - type: regex part: body group: 1 regex: - '"(v\d+.\d+.\d+.?\d?)"' # digest: 4a0a004730450220335e8f15c3f33a71df12a578f9606141ed004d53278412aceb6d329422bd2c10022100b2a7e39988b9bcfb0b399a086ea9fb433599d7e930fe265f43e0e1b166e7cebc:922c64590222798bb761d5b6d8e72950