security2 publishers
Poisoned Web-to-Lead submissions made Salesforce Agentforce leak CRM data past Trusted URLs
Zenity Labs found three Salesforce Agentforce bugs that let a planted sales lead drive zero-click CRM data theft and Slack phishing. Each attack began with one poisoned lead-form submission, and Salesforce fixed all three within 79 days of Zenity's report.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+15
- Incentives40
- Confidence62