Executive brief
A cross-site scripting (XSS) vulnerability in Fortra Cobalt Strike Teamserver allows a remote attacker to execute arbitrary HTML or code by supplying a malformed username field within a Beacon configuration. Exploitation requires the attacker to inspect a Cobalt Strike payload and modify the username field to include malicious content.
Affected products
- Fortra (HelpSystems) Cobalt Strike up to (including) 4.7
Timeline
- 2022-09-21: disclosed: NVD Published Date
- 2023-03-30: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-09-20: patched: Vendor released out-of-band update 4.7.1 to address the issue
- 2023-03-30: exploited: Reported as exploited in the wild per CISA KEV entry