Web Hack List

Collected research

Salesforce Lightning - An in-depth look at exploitation vectors for the everyday community

Salesforce Lightning - An in-depth look at exploitation vectors for the everyday community — Enumerated

Guest (unauthenticated) users of Salesforce Lightning communities can call built-in Aura controller methods and @AuraEnabled Apex methods that skip object-, field-, and record-level authorization. This lets an attacker enumerate custom objects and pull PII and other records, and abuse insecure custom methods to read or tamper with other users' data such as case attachments.

Record

Document
Salesforce Lightning - An in-depth look at exploitation vectors for the everyday community — Enumerated
Researcher
Aaron Costello
Published by
Enumerated
Date
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Aaron Costello, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .