Vulnerability CVE-2024-38453


Published: 2024-07-03

Description:
The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current version is 11 as of mid-2024.

 References:
https://appexchange.salesforce.com/appxListingDetail?listingId=a0N3A00000FKAoOUAX
https://deneyed.com/blog/avalara/

Copyright 2026, cxsecurity.com

 

Back to Top