[Facebook] Page Admin disclosed in Event Cover Photo

 A Page Admin who has created an App using "Creator App" would disclose his personal Profile if he uploaded a Cover Photo to that Event because of missing attribution setup.

Timeline -

Reported - Sunday, March 17, 2019

Triaged - Thursday, March 21, 2019

On Tuesday, July 9, 2019 marked Duplicate saying -

"This is actually a duplicate of another report you submitted (XXXXX) related to FB4A. The Creators app was not updated to pull in the fix that was made at that time, but the fix would have been the same."

The report for FB4A is disclosed here.

Popular posts from this blog

[Google] Access to BGP server + DOM XSS

[Google] YouTube "restconf" Swagger-UI XSS

[Google] Disclose hidden Blogger profile Display name and Profile photo