Root cause
Configuration values were concatenated into generated JavaScript without context-safe serialization. Stored data thereby acquired the authority of executable output.
Demonstrated impact
The researcher reports stored script execution in consuming pages and potential account compromise. The article does not fully establish configuration-write prerequisites or independently substantiate its broader deployment and employee-system impact claims.
Lessons for review
- Keep configuration data separate from executable source; use context-appropriate serialization and structured interfaces.
- Treat shared analytics code as part of the consuming application’s trusted computing base.
- Document configuration-write permissions, downstream consumers and remediation coverage independently; do not infer universal compromise from shared distribution.
Award and evidence
Only Bug #2 is represented; Bug #1 has a distinct award and report identity. No awards are summed. The source uses $. USD is inferred from official 2020 program reporting, five years before this award, rather than an individual payment receipt. No bonus or settlement is established.
Read the primary article and separately assigned reward timeline; reviewed official currency context and checked the existing report inventory for duplicate identity.
- Researcher-reported award; neither vendor confirmation of this individual award nor payment settlement was established.
- USD denomination uses official program context published five years before the award and is not an individual payment audit.
- Original publication remains unknown; current archive dates must not inflate recency.
- Only the backend configuration-to-script finding, labeled Bug #2, is included. The article also describes a different client-side finding with a separate award.
- Configuration-write prerequisites, remediation implementation and broad deployment or employee-system consequences are not independently verified.
- The narrative places investigation of Bug #2 after reporting Bug #1, while the labeled timeline dates Bug #2 first. Recorded event dates follow the explicit labels; no corrected chronology is inferred.
Recorded timeline
- Reported
- 2024-11-22explicit · Timeline entry specifically identified as Bug #2.
- Awarded
- 2025-01-16explicit · Timeline entry specifically identified as Bug #2.
- Fixed
- 2025-01-03explicit · Timeline entry specifically identified as Bug #2.
Sources and provenance
- Multiple XSS in Meta Conversion API Gateway Leading to Zero-Click Account Takeover Youssef Sammouda · reviewed 2026-10-03
- Facebook Bug Bounty and BountyCon US-dollar reporting Dan Gurfinkel / Facebook · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.