11 ms·
My guess is leaked from a misconfigured force.com site often used as a support portal or kb. Up until recently they came misconfigured by default to allow publi
by cjonas 1y ago
My guess is leaked from a misconfigured force.com site often used as a support portal or kb. Up until recently they came misconfigured by default to allow public access to the basic info of accounts, contact, opportunity through list view endpoints.
Back in 2019 I had a client affected by this (luckily caught by a white hat). Curious, I searched *.site.force.com and found thousands of potentially impacted sites (vulnerability could be tested without exfil of any data). In recent years SF has had many security patches to try and close these holes, but my understanding is most required action by the admin to take effect.
I was always confused how SF managed to keep this out of the news.