Back to directory
WRITEUP #3721

Disclose leads form details of any Facebook Business Account or Facebook Page (Bug Bounty)

IDORGraphQL
by@amineaboud(Amine Aboud)
Program
Meta / Facebook
Published
May 23, 2021
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://amineaboud.medium.com/disclose-leads-form-details-of-any-facebook-business-account-or-facebook-page-bug-bounty-7ecae6cff312
RELATED WRITEUPS
The Butterfly Effect: Turning Overlooked - Misconfigurations into Zero Click Account Takeover
APIGraphQL
Zomatoooo! IDOR in Saved Payments
IDOR
Authorization bypass due to cache misconfiguration
APIAuthorization bypass
How I got my first $13500 bounty through Parameter Polluting (HPP)
IDORXSS
A Creative Way To Get Someones YouTube Videos Deleted + A Copyright Strike Against Their YouTube Channel
IDORBroken Access Control

Built with ❤️ by Shubham Rawat