Salesforce Marketing Cloud Vulnerability Opened Door to Email Data Exposure
ID: ec7ea46d-2457-542a-84ae-1e14eab5787e
STIX ID: report--ec7ea46d-2457-542a-84ae-1e14eab5787e
Feed Name: cybersecurityNews.com
Threat Score
Researchers discovered and reported critical vulnerabilities in Salesforce Marketing Cloud that combined template-injection flaws in AMPScript/SSJS with a weak, static XOR-based query-string encryption, enabling attackers to decrypt and forge email view links and read emails and contact data across multiple tenants; Salesforce patched the issues, issued CVEs, switched to AES-GCM, expired old links, and reported no evidence of unauthorized access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
