[Page Analyst] Inviting group member to join watch party on behalf page

It is possible for page analyst to invite another group-linked-page member to watch party on behalf the page itself.

Steps :

1. As page analyst create a watch party in group and you will redirect to https://www.facebook.com/groups/<Group ID>/wp/<Watch Party>

2. Once you redirect, change the url to https://www.facebook.com/groups/<Group ID>/wp/<Watch Party>/?av=<Page ID>

3. Now go to invite menu and invite any group member and they will receive the notification from the page.

Here is the video, please skip to 0:55 for the proof of concept.


Facebook Team fix the endpoint but the root cause of this issue is from the graphql.

Here is another POC (Using FB Android Acc Token) :




Impact :

This would allow a group-linked Page Analyst to be able to invite Group members to join the watch party as the Page instead of their normal user

Timeline :

22 Aug 2018    : Report to Facebook
25 Aug 2018    : Triaged
6 Sept 2018      : First steps is fix
23 Sept 2018    : Send another information 
04 Oct 2018     : Bounty Awarded $500   
10 Jan 2019      : All Fixed by Facebook Team


Comments

Popular posts from this blog

Cara Membuat Kertas Penghantar Listrik Dengan Conductive Ink

Disclose the Facebook Learning Unit Group Insight

Cara Mengatasi "Disk Write Error" di DotA 2.