CVE-2020-36844
20.04.2025, 22:15
The KnowBe4 Security Awareness Training application before 2020-01-10 allows reflected XSS. The response has a SCRIPT element that sets window.location.href to a JavaScript URL.
Vendor | Product | Version |
---|---|---|
knowbe4 | security_awareness_training | 𝑥 < 2020-01-10 |
𝑥
= Vulnerable software versions