Vulnerability Description
A Cross-Site Scripting (XSS) vulnerability in the search function of Q4 Inc Investor Relations Platform v5.147.1.2 allows attackers to execute arbitrary Javascript via injecting a crafted payload into the SearchTerm parameter.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://docs.google.com/document/d/15vZXyzddcOv61sFSb3Lf9Dg1rnZ9n3Q6ANoa82jzcNA/
- https://gist.github.com/k4nt0r/6ee5bfe9215cb10a436a03c67cf908fd
- https://docs.google.com/document/d/15vZXyzddcOv61sFSb3Lf9Dg1rnZ9n3Q6ANoa82jzcNA/
FAQ
What is CVE-2025-29526?
CVE-2025-29526 is a vulnerability with a CVSS score of 6.1 (MEDIUM). A Cross-Site Scripting (XSS) vulnerability in the search function of Q4 Inc Investor Relations Platform v5.147.1.2 allows attackers to execute arbitrary Javascript via injecting a crafted payload into...
How severe is CVE-2025-29526?
CVE-2025-29526 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-29526?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.