CVE-2024-28741 is a pre-authentication stored cross-site scripting (XSS) vulnerability in the NorthStar C2 command and control framework. The vulnerability exists in the way agent registration data, specifically the agent ID, is logged and displayed unsanitized in the operator's web panel logs (logs.php). An unauthenticated attacker can register multiple malicious agents with specially crafted IDs, incrementally constructing a persistent JavaScript payload in the logs page. When an operator views the logs, the payload executes in their browser context, enabling further attacks such as session hijacking and remote code execution (RCE) on all connected agents. The vulnerability is due to insufficient input sanitization in the agent registration and log display processes.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (modules/exploits/windows/http/northstar_c2_xss_to_agent_rce.rb) that exploits a stored XSS vulnerability (CVE-2024-28741) in NorthStar C2 prior to commit 7674a44 (March 11, 2024). The exploit targets the NorthStar C2 web interface, allowing an unauthenticated attacker to inject a malicious XSS payload via simulated agent registration. When an administrator views the logs page, the XSS executes, hijacking their session. The module then uses the stolen session to enumerate all live agents (typically Windows hosts) and issues arbitrary commands to them, achieving remote code execution. The exploit can also optionally kill the agent process. The module interacts with several HTTP endpoints on the NorthStar C2 server, including /getin.php, /clients.php, /functions/setCommand.nonfunction.php, /getresponse.php, and /login.php. The payload is customizable and delivered as a command to the agent. The exploit requires the attacker to configure a listener (SRVHOST) and is operational, providing real RCE on vulnerable deployments. The code is written in Ruby and is designed to be used within the Metasploit framework.
This repository contains a proof-of-concept exploit for CVE-2024-28741, a stored XSS vulnerability in NorthStar C2 v1.0. The exploit is implemented in a single Python script (exploit.py) and is accompanied by a README.md that explains the vulnerability and provides background information. The exploit works by sending a series of malicious agent registration requests to the NorthStar C2 teamserver, incrementally constructing a JavaScript payload in the logs web page. When an administrator views the logs, the XSS is triggered, allowing the attacker to steal the admin's session cookie. The script then uses the stolen session to enumerate online agents and execute arbitrary commands on them, including downloading and running a DLL payload from the attacker's server. The exploit demonstrates full remote code execution on agent hosts. The code is operational and includes all necessary logic to perform the attack, including a local HTTP server to receive the stolen cookie and orchestrate the attack chain. The main endpoints involved are the NorthStar C2 teamserver (http://192.168.1.4:80) and the attacker's payload server (http://192.168.1.6:8000).
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.