Vulnerability Description
W. W. Norton InQuizitive through 2025-04-08 allows students to insert arbitrary records of their quiz performance into the backend, because only client-side access control exists.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wwnorton | Inquizitive | <= 2025-04-08 |
Related Weaknesses (CWE)
References
- https://medium.com/@JIT_Shellcode/inquizitive-client-side-injection-lms-trust-byExploitThird Party Advisory
- https://medium.com/@JIT_Shellcode/inquizitive-client-side-injection-lms-trust-byExploitThird Party Advisory
FAQ
What is CVE-2025-32808?
CVE-2025-32808 is a vulnerability with a CVSS score of 7.7 (HIGH). W. W. Norton InQuizitive through 2025-04-08 allows students to insert arbitrary records of their quiz performance into the backend, because only client-side access control exists.
How severe is CVE-2025-32808?
CVE-2025-32808 has been rated HIGH with a CVSS base score of 7.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-32808?
Check the references section above for vendor advisories and patch information. Affected products include: Wwnorton Inquizitive.