CVE-2020-36845

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Apr 20, 2025
Updated: May 13, 2025
CWE ID 601

Summary

CVE-2020-36845 is a vulnerability affecting the KnowBe4 Security Awareness Training application version prior to 2020-01-10. This issue involves a redirect function that fails to validate the destination URL before implementation, allowing an attacker to manipulate users into visiting malicious websites. The response contains a SCRIPT element, which sets window.location.href to an arbitrary HTTPS URL, increasing the risk of phishing attacks and data exfiltration. This vulnerability could potentially be exploited through targeted emails or links, compromising the security of the affected organization's employees and their sensitive data.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share