CVE-2022-39197
CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the Cobalt Strike teamserver. To exploit the vulnerability, one must first inspect a Cobalt Strike payload, and then modify the username field in the payload (or create a new payload with the extracted information and then modify that username field to be malformed).
| Vendor | n/a |
| Product | n/a |
| Published | Sep 22, 2022 |
| Last Updated | Oct 21, 2025 |
โ ๏ธ Actively Exploited โ Act Now
Get instant alerts for n/a n/a
This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2022-39197.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
n/a / n/a
n/a