Merge pull request #4825 from Ph33rr/master

Update salesforce-aura.yaml
patch-1
Prince Chaddha 2022-07-14 12:41:40 +05:30 committed by GitHub
commit 72c36147c5
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 4 additions and 1 deletions

View File

@ -2,10 +2,11 @@ id: salesforce-aura
info:
name: Detect the exposure of Salesforce Lightning aura API
author: aaron_costello (@ConspiracyProof)
author: aaron_costello (@ConspiracyProof),Ph33rr
severity: info
reference:
- https://www.enumerated.de/index/salesforce
- https://github.com/Ph33rr/cirrusgo (test endpoint)
tags: aura,unauth,salesforce,exposure
requests:
@ -14,6 +15,8 @@ requests:
- "{{BaseURL}}/aura"
- "{{BaseURL}}/s/sfsites/aura"
- "{{BaseURL}}/sfsites/aura"
- "{{BaseURL}}/s/aura"
- "{{BaseURL}}/s/fact"
body: "{}"