Facebook Bug Bounty:See unpublished jobs of any page.

Facebook rolled out Job Posting feature for pages last year.But the feature was only available in  US and Canadian business page.However one of my pages got JOB feature this year.


Steps to reproduce:

Made a graphql call to the following endpoint and in response got Unpublished JOB of the page.


How I got the graphql call: While browsing Facebook APP I noticed a new option named "Manage Jobs".I clicked on it then I selected my page and it redirected me to my page's JOB list.After selecting page I intercepted the HTTPS request and noticed that it is making graphql call.

Video PoC:



Timeline:

Thursday, February 15, 2018 at 3:14pm: Report Sent
Friday, February 23, 2018 at 11:16pm: Triaged
Sunday, February 25, 2018 at 7:13pm: Replied saying the issue is not fixed.
Tuesday, February 27, 2018 at 5:57pm: Triaged
Thursday, March 1, 2018 at 4:22am: Fixed
Sunday, March 11, 2018 at 6:55pm: Fix Confirmed
Wednesday, March 14, 2018 at 4:14pm: $1000 Bounty




Comments

  1. what is doc_id in graphql call u filled in the video/screenshot sir?

    ReplyDelete

Post a Comment