Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
5158Blind XSS in Spotify%27s Salesforce Integration Blind XSS Salesforce Spotify Mohammed Diaa (@mhmdiaa) Bug Bounty2016-07-192023-06-13
4221Leaked Salesforce API access token at IKEA.com Information disclosure Salesforce Ikea Jonathan Bouman (@JonathanBouman) Bug Bounty2019-04-042023-06-13
2508Exploiting Open Redirect - Whitelist Bypass Using Salesforce Environment Open redirect Token theft Salesforce NA Gaurav Nayak (@4auvar) Bug Bounty2021-06-022023-06-13
1678A Large-scale and Longitudinal Measurement Study of DKIM Deployment Email spoofing Phishing Google Mailchimp Sendgrid Salesforce Chuhan Wang Bug Bounty2022-04-012023-06-13
1366Tableau Server Leaks Sensitive Information From Reflected XSS Reflected XSS Salesforce Simon Bouchard (@SimTwisted) Bug Bounty2022-07-142023-06-13
1220Salesforce bug hunting to Critical bug Information disclosure Salesforce NA Vuk Ivanovic Bug Bounty2022-08-152023-06-13
840Security and Privacy Failures in Popular 2FA Apps Cryptographic issues LastPass Google Twilio Microsoft Duo Salesforce Latch Zoho Conor Gilsenan Bug Bounty2022-11-112023-06-13
166Exploits Explained: Permission misconfiguration within Salesforce JavaScript Remoting tokens used for Apex Controllers Salesforce Security misconfiguration Broken Access Control NA Mahmoud Gamal (@Zombiehelp54) Bug Bounty2023-04-212023-06-13
38Ghost Sites: Stealing Data From Deactivated Salesforce Communities Salesforce Security misconfiguration NA Nitay Bachrach Bug Bounty2023-05-312023-06-13