CVE-2022-39197

MEDIUM KEV

Helpsystems Cobalt Strike < 4.7.1 - XSS

Title source: rule

Description

An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the Cobalt Strike teamserver. To exploit the vulnerability, one must first inspect a Cobalt Strike payload, and then modify the username field in the payload (or create a new payload with the extracted information and then modify that username field to be malformed).

Exploits (16)

nomisec WORKING POC 387 stars
by its-arun · local
https://github.com/its-arun/CVE-2022-39197
nomisec WORKING POC 320 stars
by burpheart · poc
https://github.com/burpheart/CVE-2022-39197-patch
nomisec WORKING POC 74 stars
by burpheart · client-side
https://github.com/burpheart/cve-2022-39197
nomisec WORKING POC 47 stars
by xzajyjs · remote
https://github.com/xzajyjs/CVE-2022-39197-POC
nomisec SUSPICIOUS 38 stars
by xiao-zhu-zhu · poc
https://github.com/xiao-zhu-zhu/pig_CS4.4
nomisec SUSPICIOUS 18 stars
by lovechoudoufu · poc
https://github.com/lovechoudoufu/about_cobaltstrike4.5_cdf
nomisec WORKING POC 17 stars
by yqcs · remote
https://github.com/yqcs/CSPOC
nomisec WORKING POC 13 stars
by TheCryingGame · remote
https://github.com/TheCryingGame/CVE-2022-39197-RCE
nomisec WORKING POC 7 stars
by 4nth0ny1130 · poc
https://github.com/4nth0ny1130/CVE-2022-39197-fix_patch
nomisec WORKING POC 7 stars
by hluwa · poc
https://github.com/hluwa/cobaltstrike_swing_xss2rce
nomisec STUB 3 stars
by safe3s · poc
https://github.com/safe3s/CVE-2022-39197
nomisec WORKING POC 2 stars
by Romanc9 · poc
https://github.com/Romanc9/Gui-poc-test
nomisec WORKING POC 2 stars
by adeljck · client-side
https://github.com/adeljck/CVE-2022-39197
nomisec WRITEUP 1 stars
by purple-WL · poc
https://github.com/purple-WL/Cobaltstrike-RCE-CVE-2022-39197
nomisec WRITEUP
by zeoday · poc
https://github.com/zeoday/cobaltstrike4.5_cdf-1
vulncheck_xdb WORKING POC
client-side
https://github.com/burpheart/CS_mock

Scores

CVSS v3 6.1
EPSS 0.1964
EPSS Percentile 95.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CISA KEV 2023-03-30
VulnCheck KEV 2023-01-17
InTheWild.io 2023-03-30
ENISA EUVD EUVD-2022-41742
CWE
CWE-79
Status published
Products (1)
helpsystems/cobalt_strike < 4.7.1
Published Sep 22, 2022
KEV Added Mar 30, 2023
Tracked Since Feb 18, 2026