Facebook Open Redirect Vulnerability

An independent security researcher, who is also a founder of  illSecure.com name as Junaid Hussain, has identified an open redirect vulnerability in Facebook.
This vulnerability was reported 2 month ago to the Facebook, but as this have the low risk vulnerability hence Junaid have decided to publish it publicly. This vulnerability is not fixed yet but Facebook is working to fixed it up.
This vulnerability is not fixed yet but Facebook is working to fixed it up.

Junaid added that “An attacker can add a random invalid value to the parameters ‘app_id’ and/or ‘client_id’ and then change the value of the parameter ‘redirect_uri’ and redirect Facebook users to malicious sites such as phishing sites or sites with malware.”

Video Demo

