Vulnerability Description
W. W. Norton InQuizitive through 2025-04-08 allows students to conduct stored XSS attacks against educators via a bonus description, feedback.choice_fb[], or question_id.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wwnorton | Inquizitive | <= 2025-04-08 |
Related Weaknesses (CWE)
References
- https://medium.com/@JIT_Shellcode/inquizitive-client-side-injection-lms-trust-byExploitThird Party Advisory
- https://medium.com/@JIT_Shellcode/inquizitive-client-side-injection-lms-trust-byExploitThird Party Advisory
FAQ
What is CVE-2025-32809?
CVE-2025-32809 is a vulnerability with a CVSS score of 6.4 (MEDIUM). W. W. Norton InQuizitive through 2025-04-08 allows students to conduct stored XSS attacks against educators via a bonus description, feedback.choice_fb[], or question_id.
How severe is CVE-2025-32809?
CVE-2025-32809 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-32809?
Check the references section above for vendor advisories and patch information. Affected products include: Wwnorton Inquizitive.