CVE-2022-42948
π₯ Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
Vulnerability Description
Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.
Affected Platforms (CPE)
π¦
Helpsystems
Cobalt Strike
= 4.7.1
