private-data-exposure

1 article
sort: new top best
clear filter
0 6/10

An IDOR vulnerability in Facebook Analytics allows users with analyst roles to access private dashboard charts by manipulating the 'chartID' parameter in a GraphQL request, disclosing chart names and data that should only be visible to the dashboard owner.

Facebook Analytics Sarmad Hassan CVE not assigned
bugreader.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details