[Page Analyst] Inviting group member to join watch party on behalf page

It is possible for page analyst to invite another group-linked-page member to watch party on behalf the page itself.

Steps :

1. As page analyst create a watch party in group and you will redirect to https://www.facebook.com/groups/<Group ID>/wp/<Watch Party>

2. Once you redirect, change the url to https://www.facebook.com/groups/<Group ID>/wp/<Watch Party>/?av=<Page ID>

3. Now go to invite menu and invite any group member and they will receive the notification from the page.

Here is the video, please skip to 0:55 for the proof of concept.


Facebook Team fix the endpoint but the root cause of this issue is from the graphql.

Here is another POC (Using FB Android Acc Token) :




Impact :

This would allow a group-linked Page Analyst to be able to invite Group members to join the watch party as the Page instead of their normal user

Timeline :

22 Aug 2018    : Report to Facebook
25 Aug 2018    : Triaged
6 Sept 2018      : First steps is fix
23 Sept 2018    : Send another information 
04 Oct 2018     : Bounty Awarded $500   
10 Jan 2019      : All Fixed by Facebook Team


Comments

Popular posts from this blog

[XSLeaks] Tracking User with Page Admin/Editor/Moderator roles on Third Party Website

Disclose the Facebook Learning Unit Group Insight

Cara Mengatasi "Disk Write Error" di DotA 2.