Back to directory
WRITEUP #1912

Header spoofing via a hidden parameter in Facebook Batch GraphQL APIs

APIGraphQLSecurity misconfiguration
by@xdavidhu(David Schütz)
Bounty
3,000
Program
Meta / Facebook
Published
Nov 21, 2022
Added to HackDex
Nov 22, 2022
Read Full Writeuphttps://feed.bugs.xdavidhu.me/bugs/0017
RELATED WRITEUPS
Authorization bypass due to cache misconfiguration
APIAuthorization bypass
The Butterfly Effect: Turning Overlooked - Misconfigurations into Zero Click Account Takeover
APIGraphQL
Exploiting Broken Authentication Control In GraphQL
CloudGraphQL

Built with ❤️ by Shubham Rawat