First published: Wed Apr 23 2025(Updated: )
A Cross-Site Scripting (XSS) vulnerability in the search function of Q4 Inc Investor Relations Platform v5.147.1.2 allows attackers to execute arbitrary Javascript via injecting a crafted payload into the SearchTerm parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Q4 Investor Relations Platform |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-29526 is classified as a high-severity Cross-Site Scripting (XSS) vulnerability.
To fix CVE-2025-29526, validate and sanitize input in the SearchTerm parameter to prevent the injection of malicious payloads.
CVE-2025-29526 affects Q4 Inc Investor Relations Platform version 5.147.1.2.
CVE-2025-29526 allows attackers to execute arbitrary JavaScript, potentially compromising user data and session security.
Yes, CVE-2025-29526 can be exploited without authentication, making it particularly dangerous.