CVE-2022-39197
MEDIUMCISA KEV
Fortra Cobalt Strike Teamserver Cross-Site Scripting (XSS) Vulnerability
Record summary
CVE-2022-39197 has a selected CVSS score of 6.1 (medium); EIP currently links 15 repository PoCs. CISA lists CVE-2022-39197 in KEV.
Description
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the Cobalt Strike teamserver. To exploit the vulnerability, one must first inspect a Cobalt Strike payload, and then modify the username field in the payload (or create a new payload with the extracted information and then modify that username field to be malformed).
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · Mar 30, 2023 · CISA
- VulnCheck KEV
- Listed · Jan 17, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Repository PoCs
- 15
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 28, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Cobalt StrikeBrowse Fortra / Cobalt Strike | CISA | Version data not supplied | |
Proofs of concept
Showing 12 of 15Repository PoCs
GitHubburpheart/CS_mockRepository PoCby burpheartStars: 74Not analyzed3 files
GitHubsafe3s/CVE-2022-39197Repository PoCby safe3sStars: 3Not analyzed2 files
GitHubburpheart/cve-2022-39197Repository PoCby burpheartStars: 73Not analyzed2 files
GitHubxzajyjs/CVE-2022-39197-POCRepository PoCby xzajyjsStars: 47Not analyzed7 files
GitHubyqcs/CSPOCRepository PoCby yqcsStars: 17Not analyzed11 files
GitHubpurple-WL/Cobaltstrike-RCE-CVE-2022-39197Repository PoCby purple-WLStars: 1Not analyzed1 file
GitHublovechoudoufu/about_cobaltstrike4.5_cdfRepository PoCby lovechoudoufuStars: 18Not analyzed1 file
GitHubburpheart/CVE-2022-39197-patchRepository PoCby burpheartStars: 317Not analyzed5 files
GitHubhluwa/cobaltstrike_swing_xss2rceRepository PoCby hluwaStars: 7Not analyzed9 files
GitHub4nth0ny1130/CVE-2022-39197-fix_patchRepository PoCby 4nth0ny1130Stars: 7Not analyzed4 files
GitHubits-arun/CVE-2022-39197Repository PoCby its-arunStars: 387Not analyzed8 files
GitHubTheCryingGame/CVE-2022-39197-RCERepository PoCby TheCryingGameStars: 13Not analyzed10 files
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-39197 cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-39197 cobaltstrike.com
https://www.cobaltstrike.com/blog/out-of-band-update-cobalt-strike-4-7-1 cobaltstrike.com
https://www.cobaltstrike.com/blog/tag/release