PT-2025-17416 · Knowbe4 · Knowbe4 Security Awareness Training

Published

2025-04-20

·

Updated

2025-05-13

·

CVE-2020-36845

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions KnowBe4 Security Awareness Training versions prior to 2020-01-10
Description The issue concerns a redirect function in the application that fails to validate the destination URL before redirecting. This allows the response to contain a SCRIPT element that sets window.location.href to an arbitrary https URL.
Recommendations For versions prior to 2020-01-10, consider disabling the redirect function until a fix is applied to prevent potential exploitation. Restrict access to the redirect functionality to minimize risk. Avoid using the window.location.href variable in the affected redirect function until the issue is resolved.

Exploit

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2020-36845

Affected Products

Knowbe4 Security Awareness Training