Today I have discovered a 0day at pans and company that allows you to make a reverse-xss plain attack on the bill.
A second bug it is not a 0day, but stands to make you think if the food is cheaper if you don't want a "BUEN PROVECHO".
Take a look:
NOTE: Serial IDs, hour, place and personal information has been altered for privacy. So don't don't take them seriously.
|

Yup..i'm also thinking about how to exploit this reverse-xss input. hahah
|