CVE-2025-29526

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Apr 23, 2025
Updated: Apr 29, 2025
CWE ID 79

Summary

CVE-2025-29526 is a newly disclosed Cross-Site Scripting (XSS) vulnerability affecting the search function of Q4 Inc's Investor Relations Platform version 5.147.1.2. Malicious actors can exploit this weakness by injecting custom JavaScript code into the SearchTerm parameter. Successful attacks may result in unauthorized access to user sessions, data theft, or even system takeover. Users are strongly advised to apply the necessary security patches as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share