Insufficient URI encoding in restforce before 3.0.0 allows attacker to inject arbitrary parameters into Salesforce API requests.
References
Link | Resource |
---|---|
https://github.com/restforce/restforce/pull/392 | Issue Tracking Third Party Advisory |
Configurations
Information
Published : 2018-08-03 13:29
Updated : 2023-02-28 09:55
NVD link : CVE-2018-3777
Mitre link : CVE-2018-3777
JSON object : View
CWE
CWE-172
Encoding Error
Products Affected
restforce
- restforce