PT-2022-24798 · Helpsystems · Cobalt Strike

Beichendream

·

Published

2022-09-22

·

Updated

2025-09-23

·

CVE-2022-39197

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions HelpSystems Cobalt Strike versions through 4.7
Description A Cross Site Scripting (XSS) issue was found that allows a remote attacker to execute HTML on the Cobalt Strike teamserver. To exploit this issue, an attacker must first inspect a Cobalt Strike payload, then modify the username field in the payload to be malformed.
Recommendations For versions through 4.7, as a temporary workaround, consider restricting access to the teamserver to minimize the risk of exploitation. Avoid using the username field in the affected payload until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-39197

Affected Products

Cobalt Strike