Redirect Vulnerability in KnowBe4 Security Awareness Training Application
CVE-2020-36845
6.1MEDIUM
What is CVE-2020-36845?
The KnowBe4 Security Awareness Training application prior to January 10, 2020, contains a redirect vulnerability due to inadequate validation of the destination URL. This flaw allows attackers to exploit the redirect function, enabling them to set the browser's location to a malicious HTTPS URL through a manipulated SCRIPT element. This lack of URL verification poses a risk to user safety and can lead to phishing attacks or other security breaches.
Affected Version(s)
Security Awareness Training 0 < 2020-01-10