Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c8qh-hq9w-qh3p

Опубликовано: 24 мар. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.

Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.

EPSS

Процентиль: 95%
0.19512
Средний

9.8 Critical

CVSS3

Дефекты

CWE-116
CWE-79

Связанные уязвимости

CVSS3: 9.8
nvd
почти 3 года назад

Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.

EPSS

Процентиль: 95%
0.19512
Средний

9.8 Critical

CVSS3

Дефекты

CWE-116
CWE-79