Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.
Metrics
Affected Vendors & Products
References
History
Tue, 28 Jan 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
kev
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-28T21:18:50.298Z
Reserved: 2022-10-14T00:00:00.000Z
Link: CVE-2022-42948

Updated: 2024-08-03T13:19:05.527Z

Status : Analyzed
Published: 2023-03-24T14:15:09.927
Modified: 2025-02-07T14:53:43.630
Link: CVE-2022-42948

No data.