First published: Thu Sep 22 2022(Updated: )
Fortra Cobalt Strike contains a cross-site scripting (XSS) vulnerability in Teamserver that would allow an attacker to set a malformed username in the Beacon configuration, allowing them to execute code remotely.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fortra Cobalt Strike | ||
HelpSystems Cobalt Strike | <=4.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-39197.
The title of the vulnerability is Fortra Cobalt Strike Teamserver Cross-Site Scripting (XSS) Vulnerability.
The vulnerability allows an attacker to set a malformed username in the Beacon configuration, resulting in a cross-site scripting (XSS) vulnerability that allows remote code execution.
Fortra Cobalt Strike is the affected software.
To fix this vulnerability, users should update to the latest version of Cobalt Strike (version 4.7.1 or newer) as recommended by the vendor.