Collected research
SOQL injection
SOQL Injection – How to Exfiltrate Sensitive Data in Real-World Pentests
A Salesforce-backed application proxied arbitrary object queries through a path parameter, reaching a REST query API that rejects direct calls. With row-level security not enforced, the tester enumerated over 3,000 custom object names from metadata responses and queried each one, exfiltrating confidential business records.
Record
- Document
- SOQL Injection – How to Exfiltrate Sensitive Data in Real-World Pentests
- Researcher
- Adam Borczyk
- Published by
- securitum.com
- Topic
- Injection
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Adam Borczyk, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .