insufficient-access-controls

1 article
sort: new top best
clear filter
0 8/10

A Salesforce API access token was exposed to users' browsers during file uploads on IKEA.com's customer support forms, allowing attackers to access unrestricted customer data via the Salesforce REST API. The token lacked proper permission scoping and revealed 465 object types accessible, including customer account names and phone numbers.

IKEA.com Salesforce Jonathan Bouman Zerocopter Amass Burp Suite Param Miner CVE-like-equivalent-not-assigned
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 18 hours ago · details