Re: Facebook Bug Bounty #23 – Session ID & CSRF Vulnerability

Posted by Alfie John on Feb 13

If this does work, you’d be able to enumerate _all_ Facebook users and
delete _all_ public comments. I’d say that’s pretty critical.

Alfie

Leave a Reply