CVE-2022-42948

CVE Published 2023-03-24
Related CWE(s) CWE-116: Improper Encoding or Escaping of Output
Related Vendor(s) helpsystems
Related Product(s) cobalt_strike
Exploitation Reported (CISA KEV) 2023-03-30
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References