Loading
Generated remediation guidance and an executive summary. No account required.
Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.
Use CWE-116, Helpsystems vendor hub and Cobalt Strike product page to widen CVE-2022-42948 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-39197, CVE-2022-23317 and CVE-2021-36798 for nearby disclosures in the same product family.