[Facebook] Create Albums in Groups - bypass permissions


For anyone in a Group it was possible to create posts without the Admin's approval.


While creating an Album in a Group, we get an uploader called "Try the Basic Uploader" option.

If uploaded a file which isn't supported, an empty Album is created instead. After creation, an Album post will be created with a post ID and post link, which can have interactions as likes, comments and sharing as a normal post would.

No notifications will be sent to the Admins.

Timeline -

Reported - Thursday, December 28, 2017

Marked Duplicate - Friday, December 29, 2017

This issue is fixed.