writeups.xyz writeups.xyz / Rohit Kumar (@Rohitcoder)

Title Vulnerabilities Programs Authors
CSRF from which we can create a support ticket in Victim’s Account (500$)
Victim’s Anti CSRF Token could be exposed to Third-party Applications installed on user’s Device (500$)
Page shops with a hidden Product in “Featured product section” which could be controlled by attacker (Ex Editor).
[IDOR] Delete saved credit cards from any Business Manager Account — Facebook Bug Bounty
Private Dashboards were accessible by other Admins in Analytics Dashboard
Whitehat test accounts can act as Hidden Admin with Business manager / Ad Accounts.
ByPassing fix of Domain Blocking feature in Business Manager
Business user Employees could have applied block list to all ad accounts listed in the business manager.
User Account Takeover [Password Change]— Nice Catch!
Stored XSS on Edmodo
Facebook/Workplace Bug Exposed Offsite Employee Events, Sensitive emails Putting Employees at Risk
Object name Exposure — ING Bank Responsible Disclosure Program
Facebook Bug Bounty: Email Id, Phone Number Can be exposed Through Business Manager