PT-2025-16018 · W. W. Norton · W. W. Norton Inquizitive
Jit_Shellcode
·
Published
2025-04-11
·
Updated
2025-04-11
·
CVE-2025-32809
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
W. W. Norton InQuizitive through 2025-04-08
Description:
The issue allows students to conduct stored XSS attacks against educators via a bonus description,
feedback.choice fb[], or question id. This enables malicious activities by exploiting these parameters.Recommendations:
For W. W. Norton InQuizitive through 2025-04-08, consider restricting access to the bonus description,
feedback.choice fb[], and question id parameters to minimize the risk of exploitation until a fix is available. As a temporary workaround, educators should be cautious when interacting with student-submitted content.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
W. W. Norton Inquizitive