Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-39197

Опубликовано: 22 сент. 2022
Источник: nvd
CVSS3: 6.1
EPSS Средний

Описание

An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the Cobalt Strike teamserver. To exploit the vulnerability, one must first inspect a Cobalt Strike payload, and then modify the username field in the payload (or create a new payload with the extracted information and then modify that username field to be malformed).

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:helpsystems:cobalt_strike:*:*:*:*:*:*:*:*
Версия до 4.7.1 (исключая)

EPSS

Процентиль: 95%
0.18381
Средний

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 6.1
github
больше 3 лет назад

An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the Cobalt Strike teamserver. To exploit the vulnerability, one must first inspect a Cobalt Strike payload, and then modify the username field in the payload (or create a new payload with the extracted information and then modify that username field to be malformed).

EPSS

Процентиль: 95%
0.18381
Средний

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79