A critical vulnerability in Facebook, discovered earlier this month, could allow any user to delete any photo from the popular social networking platform.
The bug was discovered by Iranian programmer Pouya Darabi, who was rewarded by Facebook with $10,000 for his discovery.
The vulnerability lies in the new polls feature that Facebook introduced earlier this month, allowing the posting of polls that include images and animated GIFs.
Darabi analyzed the new functionality and found that when creating a new poll, the Image ID (or GIF URL) included in each request sent to the Facebookcould be replaced by any user with the Image ID of any photo on the social network.
Sending a new request with a different image ID would result in the new photo appearing in the poll.
“Every time a user tries to create a poll, a request is sent containing the GIF URL or the image ID of the photo. The poll_question_data [options] [] [associated_image_id] contains the image ID of the uploaded image,” Darabi says. “When this field value is changed to any other image ID, then that image will be shown in the poll,” he adds.
Obviously, if the poll creator deletes the post, as seen in the video above, they will also delete the photo, whose Image ID was added to the request.
The researcher responsibly reported the vulnerability he discovered on November 3rd, and Facebook proceeded to patch the vulnerability on November 5th.
It should be noted, however, that this is not the first time Facebook has been called out for addressing such a vulnerability. In the past, several security issues have been reported by researchers that allowed the deletion of videos, photo albums, and comments, and even the modification of messages sent through the platform.

