CVE-2022-39197: Fortra Cobalt Strike Teamserver Cross-Site Scripting (XSS) Vulnerability
Fortra Cobalt Strike contains a cross-site scripting (XSS) vulnerability in Teamserver that would allow an attacker to set a malformed username in the Beacon configuration, allowing them to execute code remotely.
Other sources
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the Cobalt Strike teamserver. To exploit the vulnerability, one must first inspect a Cobalt Strike payload, and then modify the username field in the payload (or create a new payload with the extracted information and then modify that username field to be malformed).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-39197.
What is the title of the vulnerability?
The title of the vulnerability is Fortra Cobalt Strike Teamserver Cross-Site Scripting (XSS) Vulnerability.
What is the description of the vulnerability?
The vulnerability allows an attacker to set a malformed username in the Beacon configuration, resulting in a cross-site scripting (XSS) vulnerability that allows remote code execution.
What software is affected by this vulnerability?
Fortra Cobalt Strike is the affected software.
How can I fix this vulnerability?
To fix this vulnerability, users should update to the latest version of Cobalt Strike (version 4.7.1 or newer) as recommended by the vendor.