VYPR

InQuizitive

by W. W. Norton

CVEs (2)

  • CVE-2025-32808HigApr 11, 2025
    risk 0.50cvss 7.7epss 0.00

    W. W. Norton InQuizitive through 2025-04-08 allows students to insert arbitrary records of their quiz performance into the backend, because only client-side access control exists.

  • CVE-2025-32809MedApr 11, 2025
    risk 0.42cvss 6.4epss 0.00

    W. W. Norton InQuizitive through 2025-04-08 allows students to conduct stored XSS attacks against educators via a bonus description, feedback.choice_fb[], or question_id.