Published On: 09 Oct 2024
On Pinterest public group boards, if a collaborator is removed, they will not be able to delete Pins on the group board. However, they can still delete Pins they saved on the group board, even if the owner removes them from the group board.
This bug allows a removed collaborator to still be able to delete pins they saved on a public group board.
Step
1
Users
- User A (attacker)
- User B (victim)
Group board types
- Public
Steps
1. From User B, invite User A to your public board (use existing/create new).
2. From User A, accept the invitation > then look for any pin and save it to the group board.
3. From User B, delete User A from the group board.
4. From User A, visit the group board and try deleting the pin you saved > the pin will be deleted.