CVE-2020-36845
EUVD-2020-3079520.04.2025, 22:15
The KnowBe4 Security Awareness Training application before 2020-01-10 contains a redirect function that does not validate the destination URL before redirecting. The response has a SCRIPT element that sets window.location.href to an arbitrary https URL.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| knowbe4 | security_awareness_training | 𝑥 < 2020-01-10 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration