CVE-2024-38453: Avalara For Salesforce Cpq

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current version is 11 as of mid-2024.

Affected products

  • Avalara Avalara For Salesforce Cpq: before 7.0 (fixed in 7.0)

Published 2024-07-03. Last modified 2026-06-17.