[Facebook] Create Albums in Groups - bypass permissions

 

For anyone in a Group it was possible to create posts without the Admin's approval.

POC -

While creating an Album in a Group, we get an uploader called "Try the Basic Uploader" option.

If uploaded a file which isn't supported, an empty Album is created instead. After creation, an Album post will be created with a post ID and post link, which can have interactions as likes, comments and sharing as a normal post would.

No notifications will be sent to the Admins.

Timeline -

Reported - Thursday, December 28, 2017

Marked Duplicate - Friday, December 29, 2017

This issue is fixed.

Popular posts from this blog

[Google] Access to BGP server + DOM XSS

[Google] YouTube "restconf" Swagger-UI XSS

[Google] Disclose hidden Blogger profile Display name and Profile photo