token-bypass

1 article
sort: new top best
clear filter
0 7/10

A critical CSRF bypass vulnerability in Facebook's ads management interface where the fb_dtsg token validation could be circumvented by manipulating the show_dialog_uri parameter and using double-encoding (%253F) to bypass the initial fix, allowing arbitrary account modifications like email changes and security setting alterations without proper CSRF protection.

Facebook Pouya OWASP
blog.darabi.me · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details