Cybersecurity Alerts

Actively Exploited Vulnerabilities

← Back to Cybersecurity Alerts

CVE-2022-39197

Fortra | Cobalt StrikeAdded 2023-03-30Remediation Deadline 2023-04-20

Fortra Cobalt Strike Teamserver Cross-Site Scripting (XSS) Vulnerability

Fortra Cobalt Strike contains a cross-site scripting (XSS) vulnerability in Teamserver that would allow an attacker to set a malformed username in the Beacon configuration, allowing them to execute code remotely.

Required Action

Apply updates per vendor instructions.

Weakness Classification

CWE-20

CWE-79

References