CVE-2020-36844 | KnowBe4 Security Awareness Training prior 2020-01-10 javascript URL window.location.href cross site scripting
A vulnerability classified as problematic was found in KnowBe4 Security Awareness Training. This vulnerability affects unknown code of the component javascript URL Handler. The manipulation of the argument window.location.href leads to cross site scripting.
This vulnerability was named CVE-2020-36844. The attack can be initiated remotely. There is no exploit available.
This product is available as a managed service. Users are not able to maintain vulnerability countermeasures themselves. It is recommended to upgrade the affected component.