CVE-2025-43700: High severity Salesforce OmniStudio vulnerability
Published Jun 10, 2025
·Updated
Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of encrypted data.
This impacts OmniStudio: before Spring 2025.
Affected Software
1 affected component
Salesforce OmniStudio<Spring 2025
Event History
Jun 10, 2025
CVE Published
via MITRE·11:12 AM
Data Sourced
via MITRE·11:12 AM
DescriptionWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-43700?
CVE-2025-43700 has been classified as a high-severity vulnerability due to its potential to expose encrypted data.
2
How do I fix CVE-2025-43700?
To fix CVE-2025-43700, update Salesforce OmniStudio to the version released after Spring 2025.
3
What type of vulnerability is CVE-2025-43700?
CVE-2025-43700 is classified as an Improper Preservation of Permissions vulnerability.
4
Which versions of Salesforce OmniStudio are affected by CVE-2025-43700?
CVE-2025-43700 affects all versions of Salesforce OmniStudio prior to Spring 2025.
5
What data is exposed due to CVE-2025-43700?
CVE-2025-43700 can lead to the exposure of sensitive encrypted data in Salesforce OmniStudio.