Home

Description

A Cross-Site Scripting (XSS) vulnerability in the search function of Q4 Inc Investor Relations Platform v5.147.1.2 allows attackers to execute arbitrary Javascript via injecting a crafted payload into the SearchTerm parameter.

PUBLISHED Reserved 2025-03-11 | Published 2025-04-23 | Updated 2025-04-23 | Assigner mitre

References

docs.google.com/...f9Dg1rnZ9n3Q6ANoa82jzcNA/edit?usp=sharing exploit

docs.google.com/...f9Dg1rnZ9n3Q6ANoa82jzcNA/edit?usp=sharing

gist.github.com/k4nt0r/6ee5bfe9215cb10a436a03c67cf908fd

cve.org (CVE-2025-29526)

nvd.nist.gov (CVE-2025-29526)

Download JSON