Client-Side Enforcement of Server-Side Security vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of required permission check.  This impacts OmniStudio: before Spring 2025
History

Wed, 18 Jun 2025 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-281

Wed, 18 Jun 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of field level security controls for OmniUICard objects.  This impacts OmniStudio: before Spring 2025 Client-Side Enforcement of Server-Side Security vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of required permission check.  This impacts OmniStudio: before Spring 2025
Weaknesses CWE-602

Tue, 10 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Jun 2025 12:00:00 +0000

Type Values Removed Values Added
Description Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of field level security controls for OmniUICard objects.  This impacts OmniStudio: before Spring 2025
Weaknesses CWE-281
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Salesforce

Published: 2025-06-10T11:44:01.720Z

Updated: 2025-06-18T13:31:44.330Z

Reserved: 2025-04-16T18:32:06.819Z

Link: CVE-2025-43699

cve-icon Vulnrichment

Updated: 2025-06-10T15:18:38.809Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2025-06-10T12:15:24.357

Modified: 2025-06-18T14:15:44.040

Link: CVE-2025-43699

cve-icon Redhat

No data.