[Facebook] Fetch ex-group members


It was possible for any Facebook User to see whom have left a Secret Group without being a member of that Group.

POC -

Go to - https://developers.facebook.com/tools/explorer/145634995501895/?method=GET&path=GROUP_ID?fields=former_members&version=v2.10

With Graph Explorer Access token, make the call.

A list of USER_ID'S will be returned who have left that Secret Group.

Timeline -

Reported - Wednesday, October 25, 2017
Marked Duplicate - Wednesday, October 25, 2017
Issue is fixed.

Popular posts from this blog

[Google] Access to BGP server + DOM XSS

[Google] YouTube "restconf" Swagger-UI XSS

[Google] Disclose hidden Blogger profile Display name and Profile photo