Collected research
Salesforce Lightning - An in-depth look at exploitation vectors for the everyday community
Salesforce Lightning - An in-depth look at exploitation vectors for the everyday community — Enumerated
Guest (unauthenticated) users of Salesforce Lightning communities can call built-in Aura controller methods and @AuraEnabled Apex methods that skip object-, field-, and record-level authorization. This lets an attacker enumerate custom objects and pull PII and other records, and abuse insecure custom methods to read or tamper with other users' data such as case attachments.
Record
- Document
- Salesforce Lightning - An in-depth look at exploitation vectors for the everyday community — Enumerated
- Researcher
- Aaron Costello
- Published by
- Enumerated
- Date
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Aaron Costello, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .