Back to search
CVE-2022-39197
Published: Sep 22, 2022
Modified: Oct 21, 2025
PUBLISHED
Description
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the Cobalt Strike teamserver. To exploit the vulnerability, one must first inspect a Cobalt Strike payload, and then modify the username field in the payload (or create a new payload with the extracted information and then modify that username field to be malformed).
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://www.cobaltstrike.com/blog/tag/release/
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now