bug-bounty449
google354
xss340
microsoft283
facebook246
apple171
exploit163
rce160
malware102
account-takeover95
cve91
bragging-post84
csrf83
browser77
writeup76
privilege-escalation68
react60
authentication-bypass57
cloudflare54
dos53
node52
ssrf51
docker51
phishing50
aws48
access-control47
oauth45
smart-contract45
supply-chain44
ethereum43
web342
defi42
sql-injection41
lfi37
idor35
vulnerability-disclosure32
smart-contract-vulnerability32
info-disclosure31
race-condition31
burp-suite31
web-application31
reverse-engineering31
clickjacking31
wordpress30
information-disclosure29
cloud29
input-validation29
web-security28
reflected-xss27
solidity27
0
8/10
A Salesforce API access token was exposed to users' browsers during file uploads on IKEA.com's customer support forms, allowing attackers to access unrestricted customer data via the Salesforce REST API. The token lacked proper permission scoping and revealed 465 object types accessible, including customer account names and phone numbers.
api-token-exposure
credential-leakage
salesforce
crmapi
insufficient-access-controls
data-exfiltration
bug-bounty
responsible-disclosure
rest-api-abuse
web-form-exploitation
reconnaissance
ikea
IKEA.com
Salesforce
Jonathan Bouman
Zerocopter
Amass
Burp Suite
Param Miner
CVE-like-equivalent-not-assigned