[Page Analyst] Inviting group member to join watch party on behalf page
It is possible for page analyst to invite another group-linked-page member to watch party on behalf the page itself.
Steps :
1. As page analyst create a watch party in group and you will redirect to https://www.facebook.com/groups/<Group ID>/wp/<Watch Party>
2. Once you redirect, change the url to https://www.facebook.com/groups/<Group ID>/wp/<Watch Party>/?av=<Page ID>
3. Now go to invite menu and invite any group member and they will receive the notification from the page.
Here is the video, please skip to 0:55 for the proof of concept.
Facebook Team fix the endpoint but the root cause of this issue is from the graphql.
Here is another POC (Using FB Android Acc Token) :
Impact :
This would allow a group-linked Page Analyst to be able to invite Group members to join the watch party as the Page instead of their normal user
Timeline :
Steps :
1. As page analyst create a watch party in group and you will redirect to https://www.facebook.com/groups/<Group ID>/wp/<Watch Party>
2. Once you redirect, change the url to https://www.facebook.com/groups/<Group ID>/wp/<Watch Party>/?av=<Page ID>
3. Now go to invite menu and invite any group member and they will receive the notification from the page.
Here is the video, please skip to 0:55 for the proof of concept.
Facebook Team fix the endpoint but the root cause of this issue is from the graphql.
Here is another POC (Using FB Android Acc Token) :
Impact :
This would allow a group-linked Page Analyst to be able to invite Group members to join the watch party as the Page instead of their normal user
Timeline :
22 Aug 2018 : Report to Facebook
25 Aug 2018 : Triaged
6 Sept 2018 : First steps is fix
23 Sept 2018 : Send another information
04 Oct 2018 : Bounty Awarded $500
10 Jan 2019 : All Fixed by Facebook Team
Comments
Post a Comment