← Back to browse · API

CVE-2022-42948

Severity
CRITICAL
CVSS
9.8
EPSS
0.02706
Risk score
65.15
CISA KEV
Yes
PoC
No
Published
2023-03-24
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2022-46004, GHSA-C8QH-HQ9W-QH3P
Products
Fortra:Cobalt Strike, n/a:n/a n/a
Sources
cisa.gov CVE-2022-42948
euvd EUVD-2022-46004

Description

Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.

References