4848 | How I was able to delete any image in Facebook community question forum |
IDOR |
Meta / Facebook |
Sarmad Hassan (@JubaBaghdad) |
Bug Bounty | 2018-02-24 | 2023-06-13 |
4775 | Disclose Private Video Thumbnail from Facebook WorkPlace |
IDOR |
Meta / Facebook |
Sarmad Hassan (@JubaBaghdad) |
Bug Bounty | 2018-05-03 | 2023-06-13 |
4689 | Bypass Admin approval, Mute Member and Posting Permissions for Only admins in Facebook groups |
Authorization flaw
Logic flaw |
Meta / Facebook |
Sarmad Hassan (@JubaBaghdad) |
Bug Bounty | 2018-07-18 | 2023-06-13 |
4638 | Distorted and Undeletable Posts in Facebook Group |
Authorization flaw
Logic flaw |
Meta / Facebook |
Sarmad Hassan (@JubaBaghdad) |
Bug Bounty | 2018-08-12 | 2023-06-13 |
4541 | Make any Unit in Facebook Groups Undeletable |
Logic flaw
IDOR
Authorization flaw |
Meta / Facebook |
Sarmad Hassan (@JubaBaghdad) |
Bug Bounty | 2018-10-09 | 2023-06-13 |
4533 | Add description to Instagram Posts on behalf of other users - 6500$ |
IDOR |
Meta / Facebook |
Sarmad Hassan (@JubaBaghdad) |
Bug Bounty | 2018-10-12 | 2023-06-13 |
4525 | Add comment on a private Oculus Developer bug report |
IDOR
Authorization flaw |
Meta / Facebook |
Sarmad Hassan (@JubaBaghdad) |
Bug Bounty | 2018-10-18 | 2023-06-13 |
4328 | How I found a simple bug in Facebook without any Test |
Authorization flaw |
Meta / Facebook |
Sarmad Hassan (@JubaBaghdad) |
Bug Bounty | 2019-01-31 | 2023-06-13 |
4307 | Disclose private attachments in Facebook Messenger Infrastructure - 15,000$ |
IDOR |
Meta / Facebook |
Sarmad Hassan (@JubaBaghdad) |
Bug Bounty | 2019-02-13 | 2023-06-13 |