Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.
Metrics
Affected Vendors & Products
References
History
Wed, 22 Oct 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 28 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
kev
|
Status: PUBLISHED
Assigner: mitre
Published: 2023-03-24T00:00:00.000Z
Updated: 2025-10-21T23:15:21.818Z
Reserved: 2022-10-14T00:00:00.000Z
Link: CVE-2022-42948
Updated: 2024-08-03T13:19:05.527Z
Status : Modified
Published: 2023-03-24T14:15:09.927
Modified: 2025-10-22T00:18:11.650
Link: CVE-2022-42948
No data.