Loading HuntDB...

[URGENT] Opportunity to publish tweets on any twitters account

High
X
X (Formerly Twitter)
Submitted None

Team Summary

Official summary from X (Formerly Twitter)

The reporter discovered a flaw in the handling of Twitter Ads Studio requests which allowed an attacker to tweet as any user. By sharing media with a victim user and then modifying the post request with the victim's account ID the media in question would be posted from the victim's account. This bug was patched immediately after being triaged and no evidence was found of the flaw being exploited by anyone other than the reporter.

Reported by kedrischh

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted