Kassem Bazzoun

Published On: 07 Feb 2020

Bypassing reviews tags on "friends of friends" public videos

Privacy/Authentication
Facebook | Other
---
LOW VALID
Description

Facebook has an option that allow users to enable review tags before it appears on their post, the official describe of this option https://www.facebook.com/settings?tab=timeline§ion=tagreview&view ( If someone who you aren't friends with adds a tag to your post, you'll still be asked to review it.) .

Show Image

Impact

Bypass tag restrictions on videos that could have allowed a malicious user to get around tag review settings on videos.




Reproduction Steps

Step
1

Consider 2 users, James is the victim and Kassem is the attacker

Step
2

1. The victim James enabled the  review tags by entering to the settings -> Timeline& tagging ->Review->Review tags that people add to your posts before the tags appear on Facebook ->Enabled
https://www.facebook.com/settings?tab=timeline&section=tagreview&view

Step
3

James upload a public video on his profile .

Step
4

The attacker Kassem Bazzoun isn't a friend with James he will tag himself or anyone of his friend on James Video without asked James for a review .

Step
5

Kassem made a POST request in the Graph API using a FIRST PARTY TOKEN

Kassem used the android mobile token .

Endpoint : james_video_id/tags
Parameter : tag_uid : kassem_id


https://developers.facebook.com/tools/explorer/?method=POST&path=182042472940644%2Ftags&version=v5.0&tag_uid=574396703

Step
6

Succefully tagging without any review from James although James enabling the review option .

Timeline
.
Kassem 02 Jan 2020

Report Sent

.
Facebook 04 Jan 2020

Pre-triage Thank you for your submission. We've managed to reproduce your report and will get back to you once we have had a chance to investigate.

.
Facebook 06 Jan 2020

Triaged Thank you for reporting this information to us. We are sending it to the appropriate product team for further investigation. We will keep you upd ... See More

.
Facebook 05 Feb 2020

Bug Fixed We have looked into this issue and believe that the vulnerability has been patched. Please let us know if you believe that the patch does not res ... See More

.
Kassem 05 Feb 2020

Confirmation

.
Facebook 06 Feb 2020

Bounty Awarded You found a way to bypass tag restrictions on videos that could have allowed a malicious user to get around tag review settings on videos.

VALID