CVE-2022-39197 is a cross-site scripting (XSS) vulnerability in HelpSystems Cobalt Strike through version 4.7. The vulnerability allows a remote attacker to execute arbitrary HTML or JavaScript code on the Cobalt Strike teamserver. Exploitation requires the attacker to inspect a Cobalt Strike payload, extract and modify the username field in the payload (or create a new payload with a malformed username), and then use this to trigger the XSS condition.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository contains a proof-of-concept exploit for CVE-2022-39197. The main file, poc.py, constructs a custom binary payload mimicking a Cobalt Strike beacon, encrypts it using a provided RSA public key, and sends it to a specified C2 server endpoint via an HTTP request with the payload in the Cookie header. The script includes hardcoded endpoints (http://192.168.234.100/pixel.gif as the C2 server and http://127.0.0.1/1.jpg as an image reference in the payload) and requires the user to supply a valid RSA public key. The exploit demonstrates the ability to craft and transmit beacon-like traffic, potentially for testing Cobalt Strike beacon parsing or exploiting related vulnerabilities. The repository consists of a README and the Python proof-of-concept script, with no additional files or frameworks.
This repository provides a proof-of-concept (POC) exploit for CVE-2022-39197, a remote code execution vulnerability affecting Java applications that process SVG files using a vulnerable handler (such as Apache Batik). The exploit consists of a malicious Java JAR (EvilJar) containing an Exploit class that executes OS commands when triggered by an SVG event. The repository includes: - A Java project (EvilJar) that builds the malicious JAR file. The Exploit.java file contains code to detect the OS and execute a calculator application as a demonstration payload. - A Python script (cve-2022-39197.py) that uses Frida to inject a payload into a running process (e.g., beacon.exe), replacing a process entry with an HTML object referencing the malicious SVG file. - A sample SVG file (serve/evil.svg) that references the malicious JAR via a remote URL, which is intended to be served over HTTP. - Instructions in the README.md for building the JAR, serving the SVG, and executing the exploit. The main attack vector is network-based, requiring the victim to process a malicious SVG file that loads a remote Java archive. The exploit demonstrates remote code execution by launching a calculator, but the payload can be customized. The repository is structured with clear separation between the Java payload, the delivery SVG, and the Python injector script.
This repository provides a proof-of-concept (POC) exploit for CVE-2022-39197, an XSS vulnerability in Cobalt Strike teamserver versions 4.7 and below. The exploit demonstrates how an attacker can craft a Beacon configuration with a malicious username that, when processed by the teamserver, triggers an XSS payload. The POC specifically causes the teamserver to display an attacker-controlled image, serving as a demonstration of the vulnerability's impact (potential for remote code execution via XSS). The main exploit script is `cve-2022-39197-poc.py`, which takes an image URL and a Beacon file or URL as input. It parses the Beacon configuration (using `parse_beacon_config.py` and `beacon_utils.py`), constructs a payload that includes an HTML `<img>` tag referencing the supplied image URL, and sends it to the Cobalt Strike teamserver. The repository also includes utility scripts for parsing and handling Beacon configurations, and references external tools for deeper analysis. The exploit is a POC and does not provide a weaponized payload; it is intended to demonstrate the vulnerability by causing the teamserver to render an image. The only fingerprintable endpoint in the repository is the example image URL used in the demonstration. The code is written in Python and is structured for ease of use and integration with Beacon analysis tools.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.