FB user birth year Disclosure via “IDOR in m.facebook.com”

My second report was very simple, To confirm their fix on my 1st bug report. I tried to analysing on facebook mobile website [m.facebook.com] timeline pattern.

  1. The url patter https://m.facebook.com/UserID/year/<actual Year>gives the post and life time event happened in that timeline
  2. So I believe by sending the “Get” request in sequence by changing the year with victim’s user id, should return the victims birth post on their birth year
m.facebook.com site “birth timeline” post screenshot

3. This behaviour disclose the victim’s Birth year to other.

4. Then I have created web application and used below node script to automate the above process (for normal user)

Created Web application.
Note: Sry guys, FB Team already patched/fixed this BUG. So above mentioned application wont work as expected

5. Following are my key node.js script which gives birth year of the user

6. Following are the Facebook resonance on my second Bug Report

Please share your comments on this POC..