Stored XSS Vulnerability in W. W. Norton InQuizitive Platform
CVE-2025-32809
6.4MEDIUM
What is CVE-2025-32809?
The InQuizitive platform developed by W. W. Norton is susceptible to a stored XSS vulnerability that allows malicious students to inject scripts into the system via the bonus description, feedback.choice_fb[], or question_id fields. This exploitation can potentially compromise the security of educators' accounts by executing unauthorized scripts whenever they interact with the compromised content. It emphasizes the need for stringent input validation and user data sanitization to mitigate such security risks.
Affected Version(s)
InQuizitive 0 <= 2025-04-08
