logo

Salesforce Applications Vulnerability Could Allow Full Account Takeover

ID: 749daa1f-aa83-5d07-9060-97a32b7fe9d6

STIX ID: report--749daa1f-aa83-5d07-9060-97a32b7fe9d6

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2024-12-03

Date Updated: 2026-04-22

Author: Divya

...
...

A critical misconfiguration in Salesforce Communities and Lightning components permits Guest Users to bypass controls, retrieve records and documents via service controllers (getItems/getRecord), and reset user passwords through a vulnerable Apex controller (CA_ChangePasswordSettingController), enabling account takeover and exposure of PII; the report includes PoC request payloads and screenshots showing successful data access and password resets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.