what's up security friends, romulosec in the hood!
website: www.significados.com.br
vulnerability: html injection
proof of concept
1 . go to website
2 . in 'Buscar signifcados...' put your html code
3 . press enter and ready, your code has been run!
example: https://www.significados.com.br/?s=%3Cp%3E/*%20RomuloSec%20in%20the%20hood%20*/%3C%2Fp%3E
the end!