CVE-2020-36844
EUVD-2020-3079620.04.2025, 22:15
The KnowBe4 Security Awareness Training application before 2020-01-10 allows reflected XSS. The response has a SCRIPT element that sets window.location.href to a JavaScript URL.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| knowbe4 | security_awareness_training | 𝑥 < 2020-01-10 |
𝑥
= Vulnerable software versions