CVE-2020-36845
20.04.2025, 22:15
The KnowBe4 Security Awareness Training application before 2020-01-10 contains a redirect function that does not validate the destination URL before redirecting. The response has a SCRIPT element that sets window.location.href to an arbitrary https URL.
Vendor | Product | Version |
---|---|---|
knowbe4 | security_awareness_training | 𝑥 < 2020-01-10 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration