Varonis researchers say they recently discovered numerous publicly accessible Salesforce Communities with a configuration that allows attackers to search for information such as customer lists, support issues, and employee email addresses. In some instances, the configuration error can even allow attackers to move laterally and access data from other services tied to the Salesforce account. Salesforce Community Cloud is a platform that allows organizations to quickly set up branded Web pages and websites that customers, partners, employees, and others can use to connect and collaborate.”]

