CVE-2025-29526 – Q4 Inc Investor Relations Platform XSS

The following table lists the changes that have been made to the
CVE-2025-29526 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Apr. 23, 2025

    Action Type Old Value New Value
    Added Description A Cross-Site Scripting (XSS) vulnerability in the search function of Q4 Inc Investor Relations Platform v5.147.1.2 allows attackers to execute arbitrary Javascript via injecting a crafted payload into the SearchTerm parameter.
    Added Reference https://docs.google.com/document/d/15vZXyzddcOv61sFSb3Lf9Dg1rnZ9n3Q6ANoa82jzcNA/edit?usp=sharing
    Added Reference https://gist.github.com/k4nt0r/6ee5bfe9215cb10a436a03c67cf908fd
Share the Post:

Related Posts