HelpSystems Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for HelpSystems products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

2

In CISA KEV

2

Beyond CISA KEV

0

Sensor Observed

0

Virtual Patch Available

0

HelpSystems KEVs Added by Year

Loading...

2 HelpSystems KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2022-39197

An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on...

Confirmed In CISA 30 Mar 2023
CVE-2022-42948

Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible...

Confirmed In CISA 30 Mar 2023

Common Vulnerability Classes (CWE)

  • CWE-116 — Improper Encoding or Escaping of Output 1
  • CWE-79 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology