Cobalt Strike 4.7.1 fails to properly escape HTML tags...
Critical severity
Unreviewed
Published
Mar 24, 2023
to the GitHub Advisory Database
•
Updated Jan 29, 2025
Description
Published by the National Vulnerability Database
Mar 24, 2023
Published to the GitHub Advisory Database
Mar 24, 2023
Last updated
Jan 29, 2025
Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.
References