Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4168Reply To Instagram Stories where privacy of who can reply is set to Nobody’. Authorization flaw Meta / Facebook Baibhav Anand (@SpongeBhav) Bug Bounty2019-04-302023-06-13
4150Bypassing Instagram’s stories restriction Logic flaw Meta / Facebook Baibhav Anand (@SpongeBhav) Bug Bounty2019-05-172023-06-13
4018XX to XXX in one day Account takeover Parameter tampering WePay Baibhav Anand (@SpongeBhav) Bug Bounty2019-07-232023-06-13
3962Sending Message as page being an analyst/ advertiser? Authorization flaw Meta / Facebook Baibhav Anand (@SpongeBhav) Bug Bounty2019-08-212023-06-13
3829Bypassing the patch for my previous Instagram bug. Authorization flaw Logic flaw Meta / Facebook Baibhav Anand (@SpongeBhav) Bug Bounty2019-11-182023-06-13
3818Reply To Instagram Stories where privacy of who can reply is set to Nobody’. (Part 2) Authorization flaw Meta / Facebook Baibhav Anand (@SpongeBhav) Bug Bounty2019-11-212023-06-13
3735How I found a Privilege Escalation Bug in a private Ecommerce? Privilege escalation NA Baibhav Anand (@SpongeBhav) Bug Bounty2020-01-062023-06-13
3531Hiding ourself in close friend’s list and avoiding victim to remove us from his close friend’s list. Authorization flaw Logic flaw Meta / Facebook Baibhav Anand (@SpongeBhav) Bug Bounty2020-04-232023-06-13
3167How often do we overlook vulnerabilities? Information disclosure HackerOne Baibhav Anand (@SpongeBhav) Bug Bounty2020-09-092023-06-13
2974Hiding from a custom list is possible on who sees our post is possible making victim not remove them from the list. Logic flaw Meta / Facebook Baibhav Anand (@SpongeBhav) Bug Bounty2020-12-112023-06-13
2967Disclosing the members of private Facebook Group as a non-member. Authorization flaw Logic flaw Meta / Facebook Baibhav Anand (@SpongeBhav) Bug Bounty2020-12-152023-06-13
2949Hiding from custom story privacy list is possible in FBlite making the victim unable to remove you from the list. Logic flaw Meta / Facebook Baibhav Anand (@SpongeBhav) Bug Bounty2020-12-242023-06-13
2718Facebook Group Members Disclosure. Information disclosure Meta / Facebook Baibhav Anand (@SpongeBhav) Bug Bounty2021-03-152023-06-13
2717De-anonymize the members of a private Facebook Group as a non-member. GraphQL Information disclosure Meta / Facebook Baibhav Anand (@SpongeBhav) Bug Bounty2021-03-152023-06-13
2613Page Owners Can’t remove or change page roles of deactivated users (or if Attacker blocks the page owner) in Facebook Lite, Facebook for Android and touch.facebook.com Logic flaw Meta / Facebook Baibhav Anand (@SpongeBhav) Bug Bounty2021-04-222023-06-13