CVE-2025-43701: High severity Salesforce OmniStudio vulnerability
Published Jun 10, 2025
·Updated
Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of Custom Settings data.
This impacts OmniStudio: before version 254.
Affected Software
1 affected component
Salesforce OmniStudio<254
Event History
Jun 10, 2025
CVE Published
via MITRE·11:21 AM
Data Sourced
via MITRE·11:21 AM
DescriptionWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-43701?
CVE-2025-43701 is classified as a high-severity vulnerability due to its potential to expose sensitive Custom Settings data.
2
How do I fix CVE-2025-43701?
To fix CVE-2025-43701, update your Salesforce OmniStudio to version 254 or later.
3
What are the impacts of CVE-2025-43701?
CVE-2025-43701 can lead to unintended exposure of Custom Settings data, which may compromise sensitive information.
4
Who is affected by CVE-2025-43701?
CVE-2025-43701 affects all users of Salesforce OmniStudio versions before 254.
5
Is CVE-2025-43701 actively exploited?
As of now, there is no public evidence indicating that CVE-2025-43701 is actively being exploited in the wild.