$ techbeacon▋
CVE & Exploits

Zero‑Click ‘SalesBleed’ Flaw Lets Attackers Drain Salesforce Data via Public Forms

Zero‑Click ‘SalesBleed’ Flaw Lets Attackers Drain Salesforce Data via Public Forms

Security researchers have uncovered a new vulnerability chain, dubbed “SalesBleed,” that targets Salesforce’s Agentforce platform and enables data exfiltration without any user interaction. The flaw exploits an indirect prompt‑injection technique embedded in a publicly accessible Web‑to‑Lead form, allowing attackers to siphon confidential customer‑relationship‑management (CRM) information with a single request.

Agentforce is a suite of tools that extends Salesforce’s core capabilities, providing automation, workflow orchestration, and integration services for enterprise users. Web‑to‑Lead forms, a common feature of Salesforce implementations, let organizations collect prospect data from websites without requiring a logged‑in Salesforce session. Because these forms are designed to be open to the internet, they are often used by marketing teams to capture leads at scale.

The SalesBleed chain leverages the way Agentforce processes input from the Web‑to‑Lead endpoint. By inserting specially crafted text into a form field, an attacker can trigger a prompt injection that manipulates the downstream language model used by Agentforce for automated responses. The injected prompt coerces the model into outputting internal CRM records, which are then returned to the attacker’s server as part of the form’s normal response cycle. Crucially, the exploit does not require the victim to click a link or perform any action beyond the initial request, earning it the description of a “0‑click” attack.

If successfully executed, the vulnerability can expose a wide range of sensitive data, including contact details, sales opportunities, and proprietary business metrics stored within the Salesforce environment. Companies that rely heavily on public lead capture forms—especially those with large marketing funnels—are at heightened risk because the attack surface scales with the number of exposed endpoints. The breach could facilitate competitive intelligence gathering, phishing campaigns, or broader data‑theft operations.

The flaw was first reported by the independent security group GBHackers, who have provided technical details to Salesforce for remediation. While Salesforce has not yet issued a public advisory, standard mitigation steps include restricting public access to Web‑to‑Lead forms, applying input sanitization, and reviewing Agentforce configurations for unnecessary exposure. Security experts advise organizations to audit their Salesforce instances, enforce least‑privilege access controls, and monitor for anomalous API traffic that could indicate exploitation attempts. The discovery underscores the growing need for rigorous security testing of integrated SaaS components, particularly as AI‑driven features become more prevalent in enterprise platforms.

Source: GBHackers
Mahesh Kumar Sahoo — Mahesh covers ransomware gangs, data leak sites, and dark web marketplaces, mapping how stolen data surfaces and gets sold. Follows ShinyHunters-style groups across leak forums.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related