Salesforce - Critical - CSRF - BACKDROP-SA-CONTRIB-2026-016
This module suite implements a mapping functionality between Salesforce objects and Backdrop entities
This module does not generate or validate a cryptographically random `state` parameter to protect the authorization flow against CSRF attacks.
Additionally, the OAuth callback is accessible to most authenticated and potentially anonymous users depending on site configuration.
A CVE has been requested, and this page will be updated as soon as an official number has been issued.
All Salesforce versions prior to 1.x-1.0.1