Back to directory
WRITEUP #3311

Unauthorized access to any Facebook user’s draft profile picture frames

IDOR
by@sandeephodkasia(Sandeep Hodkasia)
Program
Meta / Facebook
Published
Oct 22, 2021
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://web.archive.org/web/20231004134528/https://appsecure.security/unauthorized-access-to-any-face-book-users-draft-profile-picture-frames/
RELATED WRITEUPS
Zomatoooo! IDOR in Saved Payments
IDOR
How I got my first $13500 bounty through Parameter Polluting (HPP)
IDORXSS
The Butterfly Effect: Turning Overlooked - Misconfigurations into Zero Click Account Takeover
APIGraphQL
A Creative Way To Get Someones YouTube Videos Deleted + A Copyright Strike Against Their YouTube Channel
IDORBroken Access Control
Bypassing ACLs – IDOR exploitation via HPP
IDORHTTP parameter pollution

Built with ❤️ by Shubham Rawat