CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.3. See the original NVD description below for full technical details.
CVE
CVE-2020-36845
Severity
MEDIUM
CVSS
5.3
EPSS
0.25%
Original NVD Description
The KnowBe4 Security Awareness Training application before 2020-01-10 contains a redirect function that does not validate the destination URL before redirecting. The response has a SCRIPT element that sets window.location.href to an arbitrary https URL.
Related CVEs
Other vulnerabilities affecting the same vendor(s)