Описание
Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.
Ссылки
- Technical DescriptionThird Party Advisory
- Vendor Advisory
- Third Party Advisory
- Technical DescriptionThird Party Advisory
- Vendor Advisory
- Third Party Advisory
- US Government Resource
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:helpsystems:cobalt_strike:4.7.1:*:*:*:*:*:*:*
EPSS
Процентиль: 95%
0.19512
Средний
9.8 Critical
CVSS3
Дефекты
CWE-116
CWE-116
Связанные уязвимости
CVSS3: 9.8
github
почти 3 года назад
Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.
EPSS
Процентиль: 95%
0.19512
Средний
9.8 Critical
CVSS3
Дефекты
CWE-116
CWE-116