Vulnerability record · CVE-2022-39197 · published 22 September 2022
CVE-2022-39197: Cobalt Strike Teamserver XSS via Malformed Payload Username Field
Helpsystems · Cobalt Strike
Cobalt Strike through 4.7 contains a cross-site scripting flaw in the teamserver that lets a remote attacker inject HTML by modifying the username field of a Cobalt Strike payload. Because the teamserver is the operator console for red-team and, in abuse cases, intrusion activity, a successful injection can compromise the operator's browser session and the server's integrity.
Description
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the Cobalt Strike teamserver. To exploit the vulnerability, one must first inspect a Cobalt Strike payload, and then modify the username field in the payload (or create a new payload with the extracted information and then modify that username field to be malformed).
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityIt is in CISA KEV with confirmed exploitation and a very high EPSS percentile, though the CVSS base score is medium and exploitation requires user interaction.
What it is
Cobalt Strike through 4.7 contains a cross-site scripting flaw in the teamserver that lets a remote attacker inject HTML by modifying the username field of a Cobalt Strike payload. Because the teamserver is the operator console for red-team and, in abuse cases, intrusion activity, a successful injection can compromise the operator's browser session and the server's integrity.
Impact
An attacker can execute HTML/script in the context of the Cobalt Strike teamserver, potentially stealing operator session data or performing actions as the operator. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.
Attack surface
Reached over the network (AV:N) with no privileges required (PR:N), but exploitation requires user interaction (UI:R) because the operator must inspect or handle a crafted payload. The description states the attacker must first inspect a payload and then modify the username field, so the attack depends on the operator processing attacker-influenced payload data.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2023-03-30, confirming real-world exploitation, and EPSS shows a 30-day probability of 0.46446 (98.755th percentile). No ransomware campaign use is documented.
What to do
- Apply the vendor out-of-band update to Cobalt Strike 4.7.1 or later per the vendor advisory.
- If immediate patching is not possible, restrict network access to the teamserver to trusted management networks only.
- Treat payloads from untrusted or unknown sources as hostile; do not inspect or import them into the teamserver.
- Monitor and validate the username field in payloads before use, and avoid importing payloads with malformed or unexpected username values.
- Follow CISA KEV required action: apply updates per vendor instructions by the due date.
Detection
- Monitor teamserver logs and HTTP traffic for payloads containing script tags or HTML in the username field.
- Alert on unexpected outbound connections or script execution originating from the teamserver host.
- Review Cobalt Strike teamserver access logs for anomalous operator sessions or payload imports.
- Hunt for known CVE-2022-39197 indicators in network traffic and endpoint telemetry around teamserver hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-39197 to the Known Exploited Vulnerabilities catalog on 30 March 2023 as "Fortra Cobalt Strike Teamserver Cross-Site Scripting (XSS) Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 20 April 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.cobaltstrike.com/blog/out-of-band-update-cobalt-strike-4-7-1/ | MitigationVendor Advisory |
| https://www.cobaltstrike.com/blog/tag/release/ | Release NotesVendor Advisory |
| https://www.cobaltstrike.com/blog/out-of-band-update-cobalt-strike-4-7-1/ | MitigationVendor Advisory |
| https://www.cobaltstrike.com/blog/tag/release/ | Release NotesVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-39197 | US Government Resource |
Track CVE-2022-39197 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-39197), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.