EUVD-2022-46004
Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 30 Mar 2023. Evidence sources: cisa_kev.
- ENISA score
- 9.8 · CVSS 3.1
- Advisory evidence
- No linked advisory details stored yet
