Salesforce Applications Vulnerability Could Allow Full Account Takeover
ID: 749daa1f-aa83-5d07-9060-97a32b7fe9d6
STIX ID: report--749daa1f-aa83-5d07-9060-97a32b7fe9d6
Feed Name: GBHackers
Threat Score
A critical misconfiguration in Salesforce Communities and Lightning components permits Guest Users to bypass controls, retrieve records and documents via service controllers (getItems/getRecord), and reset user passwords through a vulnerable Apex controller (CA_ChangePasswordSettingController), enabling account takeover and exposure of PII; the report includes PoC request payloads and screenshots showing successful data access and password resets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
