I found a vulnerability in Facebook that allowed me to send a POST request with CSRF token to any Facebook endpoints or external hosts!
It was very similar to this bug which I found in 2015.
Labels:
2016
,
bounty
,
bug
,
bypass
,
CSRF
,
exploit
,
facebook
,
facebook exploit
,
hack
,
vulnerability
I discovered a critical vulnerability in Facebook that allowed an attacker to bypasses Facebook CSRF protection!
more information about CSRF at owasp
more information about CSRF at owasp
Labels:
2015
,
bounty
,
bug
,
bypass
,
critical
,
CSRF
,
facebook
,
facebook exploit
,
vulnerability
I discovered a vulnerability in Facebook that allowed a normal user in ad account to get unauthorized admin access in that ad account
admins in ad account can add any user to their ad account with these 3 type of role :
admins in ad account can add any user to their ad account with these 3 type of role :
- admin
- advertiser
- analyst


