CVE-2024-38453
EUVD-2024-3733903.07.2024, 06:15
The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current version is 11 as of mid-2024.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| avalara | avalara_for_salesforce_cpq | 𝑥 < 7.0 | ADP |
Common Weakness Enumeration