Sunday, April 27, 2025
HomeCVE/vulnerabilityFacebook Image Removal Vulnerability allows Users to Delete any Photos

Facebook Image Removal Vulnerability allows Users to Delete any Photos

Published on

SIEM as a Service

Follow Us on Google News

Facebook recently introduced a poll feature which allows users to make votable questions as the status on both Android and iOS apps.

Security researcher Pouya Darabi found a vulnerability that allows anyone to delete any photo from the Facebook platform.

Facebook vulnerability

Darabi explains the vulnerability allows anyone can quickly change the Image ID that associated with any other image ID when sending the request to the facebook server.

Whenever a user tries to create a poll, a request containing gif URL or image id will be sent,
poll_question_data[options][][associated_image_id] contains the uploaded image id.
When this field value changes to any other images ID, that image will be shown in the poll.
After sending the request with another user image ID, a poll containing that image would be created.
- Advertisement - Google News

If the poll creator deletes the Photo, it deletes victim images as well considering it as poll property.He reported the bug on November 3 and Facebook responds quickly and fixes the bug by 5 Nov 2017.

On November 8 Facebook Awarded $10,000 as bounty for his findings. Earlier this year Security researcher Dan Melamed came with a vulnerability that allows anyone to change the Video ID to any other video on the social media platform.

Before this Darabi found a couple of vulnerabilities with Facebook, in 2015, he found a CSRF on Facebook, and he was granted $15,000.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Two Systemic Jailbreaks Uncovered, Exposing Widespread Vulnerabilities in Generative AI Models

Two significant security vulnerabilities in generative AI systems have been discovered, allowing attackers to...

New AI-Generated ‘TikDocs’ Exploits Trust in the Medical Profession to Drive Sales

AI-generated medical scams across TikTok and Instagram, where deepfake avatars pose as healthcare professionals...

Gamers Beware! New Attack Targets Gamers to Deploy AgeoStealer Malware

The cybersecurity landscape faces an escalating crisis as AgeoStealer joins the ranks of advanced...

Compliance And Governance: What Every CISO Needs To Know About Data Protection Regulations

The cybersecurity landscape has changed dramatically in recent years, largely due to the introduction...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Chrome UAF Process Vulnerabilities Actively Exploited

Security researchers have revealed that two critical use-after-free (UAF) vulnerabilities in Google Chrome’s Browser...

Spring Security Vulnerability Exposes Valid Usernames to Attackers

A newly identified security vulnerability, CVE-2025-22234, has exposed a critical weakness in the widely-used...

SAP NetWeaver 0-Day Vulnerability Enables Webshell Deployment

Cybersecurity analysts have issued a high-priority warning after several incidents revealed active exploitation of...