Get the latest tech news
Insecure Apex code plagues many Salesforce deployments.
Vulnerabilities created by insecure code could lead to data leakage or corruption, and the burden is on Salesforce customers to mitigate.
Security researchers warn that many organizations have instances of insecure Apex code in their Salesforce deployments which open serious vulnerabilities that put their data and business workflows at risk. Researchers from security firm Varonis reported finding high and critical severity vulnerabilities in the Apex code used by multiple Fortune 500 companies and government agencies, but warn that similar insecure practices are likely common inside organizations of all sizes and from all industries. Apex allows users to customize their Salesforce instances by adding additional business logic to system events, including button clicks, related record updates and Visualforce pages.
Or read this on r/technology