An old API (application programming interface) that was missed by Facebook allowed a potential attacker to take control over users’ accounts.The flaw, consisting in a mis-configured endpoint, would permit legacy REST API to make calls on behalf of any Facebook user, no authentication being necessary, only the user ID.Security researcher Stephen Sclafani discovered that using a still active REST API, that is the predecessor of Graph API, he could get unauthorized access to a Facebook account an…