Client-Side Enforcement of Server-Side Security vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of required permission check.
This impacts OmniStudio: before Spring 2025
Metrics
Affected Vendors & Products
References
History
Wed, 18 Jun 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-281 |
Wed, 18 Jun 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of field level security controls for OmniUICard objects. This impacts OmniStudio: before Spring 2025 | Client-Side Enforcement of Server-Side Security vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of required permission check. This impacts OmniStudio: before Spring 2025 |
Weaknesses | CWE-602 |
Tue, 10 Jun 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Tue, 10 Jun 2025 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of field level security controls for OmniUICard objects. This impacts OmniStudio: before Spring 2025 | |
Weaknesses | CWE-281 | |
References |
|

Status: PUBLISHED
Assigner: Salesforce
Published: 2025-06-10T11:44:01.720Z
Updated: 2025-06-18T13:31:44.330Z
Reserved: 2025-04-16T18:32:06.819Z
Link: CVE-2025-43699

Updated: 2025-06-10T15:18:38.809Z

Status : Undergoing Analysis
Published: 2025-06-10T12:15:24.357
Modified: 2025-06-18T14:15:44.040
Link: CVE-2025-43699

No data.