Skip to content
TrackPodcasts
technologyAug 17, 202534:25pending

End Of The World As We Know It: Security Leaks In Power Pages

CRM Audio

Get every episode summarized

Each time CRM Audio publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

About this episode

In this episode, we take a close look at the history of security issues in Power Pages. We start with the early days — when simple misconfigurations like unchecked table permissions and enabled OData feeds led to major data exposures. These weren't bugs, but they showed how easy it was to set things up the wrong way. We talk about how Microsoft responded and what lessons we've learned about secure defaults and clear documentation.

We then move on to more serious vulnerabilities introduced by newer features like the Web API. We explain how some of these flaws allowed access to restricted data using filters and sort clauses, and how those issues were eventually patched. These were real product-level bugs, and some were even exploited in the wild.

We also share our thoughts on external authentication providers like Google, and the risks that come with delegating authentication — including phishing techniques that can bypass protections. Finally, we reflect on how Power Pages compares to platforms like WordPress, especially when it comes to architecture and the potential for plugin-related vulnerabilities. Despite recent issues, we think the original design of Power Pages deserves credit for holding up well over time.

References

Get in touch

Hosts & guests

No transcript yet

This episode has not been transcribed. Request it and it moves to the front of the queue.

End Of The World As We Know It: Security Leaks In Power Pages

CRM Audio

0:00
34:25

More episodes

More from CRM Audio

View all episodes →