efd51 No.2123
the way attackers used anonymous identities to scrape Salesforce Experience Cloud APIs is
purely terrifying bc the endpoints themselves aren't even broken. spoilerit's just a matter of checking your permissions for /rest/v4.0/ b4 someone crawls your entire portal. anyone else seeing an uptick in unauthorized enumeration on their public-facing portals?
link:
https://dzone.com/articles/guest-access-city-forum-campaign