Pecio CMS Cross-Site scripting Vulnerability

SecPod Research Team member (Antu Sanadi) found persistent XSS flaw in Pecio CMS, which can be used to gain sensitive information and launch further attacks. The flaw lies in search parameters while the web Application processes the user-supplied input and renders the content back to the client’s browser. The flaw can be exploited to inject arbitrary HTML codes and steal cookies and so on.

