# Exploit Title : CMS Sekolahku - Indonesian School HTML Injection
# Author : Xmall75
# Vendor Homepage : www.sekolahku.web.id
# Date : 1 August 2020
# Tested on : Windows
# Dork :
intext:"Powered by sekolahku.web.id"
# Payload :
<h1>HTML Injection by Xmall75</h1>
# Step :
I found that they have 2 templates. So there will be different page you can inject.
1. First, input your payload on search console.
2. If it isn't vulnerable, then go to comment section. Input your payload there.
# Demo :
premium.sekolahku.web.id
smkn2balikpapan.sch.id
smp2rembang.sch.id
smkn7jogja.sch.id
smpn1bandarseikijang.sch.id
# xmall75.id@gmail.com