Loading vulnerability details…
CVSS v3.1
9.8
EPSS
2.71%
Published
Mar 24, 2023
Modified
Nov 3, 2025
CISA Known Exploited Vulnerability
Added: 2023-03-30 · Due: 2023-04-20
Apply updates per vendor instructions.
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses (CWE)
Affected Products (1)
References (7)