Login to any user account using other Facebook app access token (2015)
hackerone.com
hackerone.com
also, this is a bug report for imgur, not Facebook so this is super misleading title.
I’m not sure I follow this. This sounds like “phish user credentials, then use user credentials.” What am I missing?
This is related to SSO (single sign on) where imgur didn't check the source of the token.
So, if you built an app that used SSO with Facebook (so that any user can log into your app with their Facebook credentials, but without you knowing them) you could use that SSO information for your app to log into imgur as that user.
Because imgur wasn't checking that the token was from their own app. The token is just a Facebook response that says something like "this is user X and they wants to log into app Y, signed by Facebook". If you don't check Y...
I feel the bug bounty scene is very crowded and most companies will treat you as an imbecile.