Back to directory
WRITEUP #5021

Reflected XSS in graph.facebook.com leads to account takeover in IE/Edge

XSSReflected XSSAccount takeover
by@samm0uda(Youssef Sammouda)
Bounty
5,000
Program
Meta / Facebook
Published
Nov 27, 2019
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://ysamm.com/?p=343
RELATED WRITEUPS
Self-XSS to ATO via Site Features
XSSSelf-XSS
Basic HTTP Authentication Risk: Uncovering pyspider Vulnerabilities
XSSReflected XSS
Interesting Story of an Account Takeover Vulnerability
Auth BypassAccount takeover
How 100% Manual Hacking (Without Even Kali And Burp) Led To 2 Medium Vulnerabilities On YesWeHack
XSS
Bypassing CSP via URL Parser Confusions : XSS on Netlify’s Image CDN
XSSCSP bypass

Built with ❤️ by Shubham Rawat