admin-disclosure

1 article
sort: new top best
clear filter
0 5/10

A Facebook bug allowed page admins to unintentionally disclose their admin status by upgrading a page post to a life event, which would then appear on their personal profile and reveal their connection to the page when other users visited it. The vulnerability was fixed within 2 months of disclosure and the researcher received a bounty.

Facebook Dan Fabro
medium.com · dw1 · 17 hours ago · details