A cross-site scripting (XSS) vulnerability in a Salesforce subdomain allowed attackers to gather end-user credentials through trusted applications from the cloud company, researchers at infosec firm ...