CVE-2020-36845
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2020-36845 is a vulnerability affecting the KnowBe4 Security Awareness Training application version prior to 2020-01-10. This issue involves a redirect function that fails to validate the destination URL before implementation, allowing an attacker to manipulate users into visiting malicious websites. The response contains a SCRIPT element, which sets window.location.href to an arbitrary HTTPS URL, increasing the risk of phishing attacks and data exfiltration. This vulnerability could potentially be exploited through targeted emails or links, compromising the security of the affected organization's employees and their sensitive data.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.