Web Hack List

Other nomination

Salesforce Lightning - An in-depth look at exploitation vectors for the everyday community

Guest (unauthenticated) users of Salesforce Lightning communities can call built-in Aura controller methods and @AuraEnabled Apex methods that skip object-, field-, and record-level authorization. This lets an attacker enumerate custom objects and pull PII and other records, and abuse insecure custom methods to read or tamper with other users' data such as case attachments.

Record

Researcher
Aaron Costello
Published by
Enumerated
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Aaron Costello, first published at the original source. Preserved copies are kept so the citation survives its host.