CSRF from which we can create a support ticket in Victim’s Account (500$) |
|
|
|
Victim’s Anti CSRF Token could be exposed to Third-party Applications installed on user’s Device (500$) |
|
|
|
Page shops with a hidden Product in “Featured product section” which could be controlled by attacker (Ex Editor). |
|
|
|
[IDOR] Delete saved credit cards from any Business Manager Account — Facebook Bug Bounty |
|
|
|
Private Dashboards were accessible by other Admins in Analytics Dashboard |
|
|
|
Whitehat test accounts can act as Hidden Admin with Business manager / Ad Accounts. |
|
|
|
ByPassing fix of Domain Blocking feature in Business Manager |
|
|
|
Business user Employees could have applied block list to all ad accounts listed in the business manager. |
|
|
|
User Account Takeover [Password Change]— Nice Catch! |
|
|
|
Stored XSS on Edmodo |
|
|
|
Facebook/Workplace Bug Exposed Offsite Employee Events, Sensitive emails Putting Employees at Risk |
|
|
|
Object name Exposure — ING Bank Responsible Disclosure Program |
|
|
|
Facebook Bug Bounty: Email Id, Phone Number Can be exposed Through Business Manager |
|
|
|