Uploaded October 2024 | Updated September 2026, 1 week ago
Nick Dunn, IOActive Senior Security Consultant, presented an exploration into SOSL injection vulnerabilities in February 2024 during a hack::cheltenham event.
ABSTRACT:
The Salesforce platform allows a platform-specific vulnerability within the Apex code, known as SOSL injection; while conceptually similar to SQL injection, the testing and exploitation entails different payloads and approaches.
With concerns stemming from the minimal documentation available online, the exploration will attempt to shed light on the Apex code and custom API issue - its consequences and the working methods for detecting and confirming the existence of the vulnerabilities found within; probing in detail the different payloads useful for detection and exploitation, the consequences of a vulnerable site and finally, discussions on solutions to fix the occurrences of the issue.
Learn more about IOActive by visiting our website: ioactive.com
Nick Dunn, IOActive Senior Security Consultant, presented an exploration into SOSL injection vulnerabilities in February 2024 during a hack::cheltenham event.
ABSTRACT:
The Salesforce platform allows a platform-specific vulnerability within the Apex code, known as SOSL injection; while conceptually similar to SQL injection, the testing and exploitation entails different payloads and approaches.
With concerns stemming from the minimal documentation available online, the exploration will attempt to shed light on the Apex code and custom API issue - its consequences and the working methods for detecting and confirming the existence of the vulnerabilities found within; probing in detail the different payloads useful for detection and exploitation, the consequences of a vulnerable site and finally, discussions on solutions to fix the occurrences of the issue.
Learn more about IOActive by visiting our website: ioactive.com










