Home

Description

Client-Side Enforcement of Server-Side Security vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of required permission check.  This impacts OmniStudio: before Spring 2025

PUBLISHED Reserved 2025-04-16 | Published 2025-06-10 | Updated 2025-06-18 | Assigner Salesforce

Problem types

CWE-602: Client-Side Enforcement of Server-Side Security

Product status

Default status
unaffected

Any version before Spring 2025
affected

References

help.salesforce.com/s/articleView?id=004980323&type=1

cve.org (CVE-2025-43699)

nvd.nist.gov (CVE-2025-43699)

Download JSON