AppXsecurity
EN
  • English (EN)
  • Nederlands (NL)
  • Home
  • Services
    • Penetration Testing
    • Vulnerability Assessments
    • AppExchange | AgentExchange Security Review
    • Code Security Analysis
    • Configuration Security Audit
    • Security Compliance & Remediation
  • Resources
    • Case Studies
    • Security Checklist
    • Expertise
    • False Positive Report
    • Hands-On Collaboration
    • End-to-End Remediation
  • Academy
  • Contact
  • Start Learning
  • EN
    • English (EN)
    • Nederlands (NL)
  • Dashboard
  • Learning Paths
  • Latest Topics
    • Misconfiguration Abuse in Apex Callout Proxy
    • Unauthorized Outbound Access via Remote Site Settings Misconfiguration
    • Unauthorized Record Access via Inherited Sharing Call Chains
    • Session Token Leakage in Outbound Messages
    • Information Disclosure via Dynamic Object and Field Enumeration
    • View all topics
  • All Content
    • All labs
    • All topics
  • Hall of Fame
  • Get Started
  • Get Certified
    • Get certified
    • How to prepare
    • How it works
    • Practice exam
    • Exam hints and guidance
    • What the exam involves
    • FAQs
    • Validate your certification

All Labs

Explore all available hands-on labs to practice identifying and fixing Salesforce security vulnerabilities.

Latest Labs

Misconfiguration Abuse in Apex Callout Proxy

Learn how dynamic Apex callout relays can become exploitable outbound proxies.

Start Lab →

Unauthorized Outbound Access via Remote Site Settings Misconfiguration

Learn how overly dynamic endpoint selection can enable outbound callout abuse and data leakage.

Start Lab →

Unauthorized Record Access via Inherited Sharing Call Chains

Learn how mixed sharing contexts create unexpected data access through inherited call paths.

Start Lab →

Session Token Leakage in Outbound Messages

Understand how session tokens leak through outbound flows and how replay abuse happens.

Start Lab →

Featured Labs

Insecure Secrets Management

Learn secure practices for managing API keys, passwords, and sensitive data.

Start Lab →

Insecure PII Storage

Identify and remediate insecure storage of personally identifiable information.

Start Lab →

Cross-site Request Forgery (CSRF)

Practice implementing CSRF protection in Salesforce applications.

Start Lab →

Open Redirect

Learn to prevent open redirect vulnerabilities in Salesforce.

Start Lab →

View all learning materials >> View all labs

AppXsecurity
  • AppXScanner
  • AppXShield
  • Certifications
Vulnerabilities
  • Cross-site scripting (XSS)
  • SOQL Injection
  • Cross-site request forgery
  • Sharing Violation
  • Misconfiguration Abuse in Apex Callout Proxy
Customers
  • Organizations
  • Testers
  • Developers
Company
  • About
  • Careers
  • Contact
  • Legal
  • Privacy Notice
Insights
  • AppXsecurity Academy
  • Blog
  • Research

© 2025 AppXsecurity. All Rights Reserved.