Web Hack List

Collected research

SOQL injection

SOQL Injection – How to Exfiltrate Sensitive Data in Real-World Pentests

A Salesforce-backed application proxied arbitrary object queries through a path parameter, reaching a REST query API that rejects direct calls. With row-level security not enforced, the tester enumerated over 3,000 custom object names from metadata responses and queried each one, exfiltrating confidential business records.

Record

Document
SOQL Injection – How to Exfiltrate Sensitive Data in Real-World Pentests
Researcher
Adam Borczyk
Published by
securitum.com
Topic
Injection

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Adam Borczyk, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .