Reflected Cross-Site Scripting in KnowBe4 Security Awareness Training
CVE-2020-36844
6.1MEDIUM
What is CVE-2020-36844?
The KnowBe4 Security Awareness Training application prior to January 10, 2020, is susceptible to reflected Cross-Site Scripting (XSS) attacks. The vulnerability allows an attacker to inject malicious scripts into responses that can redirect users to harmful sites. When exploited, the application returns a SCRIPT element that modifies the window.location.href property to a JavaScript URL, potentially compromising user security and data integrity.
Affected Version(s)
Security Awareness Training 0 < 2020-01-10