[Facebook] Create Albums in Groups - bypass permissions
For anyone in a Group it was possible to create posts without the Admin's approval.
POC -
While creating an Album in a Group, we get an uploader called "Try the Basic Uploader" option.
If uploaded a file which isn't supported, an empty Album is created instead. After creation, an Album post will be created with a post ID and post link, which can have interactions as likes, comments and sharing as a normal post would.
No notifications will be sent to the Admins.
Timeline -
Reported - Thursday, December 28, 2017
Marked Duplicate - Friday, December 29, 2017
This issue is fixed.