CobaltStrike <=4.5 HTTP(S) listener does not determine...
High severity
Unreviewed
Published
Feb 16, 2022
to the GitHub Advisory Database
•
Updated Aug 8, 2023
Description
Published by the National Vulnerability Database
Feb 15, 2022
Published to the GitHub Advisory Database
Feb 16, 2022
Last updated
Aug 8, 2023
CobaltStrike <=4.5 HTTP(S) listener does not determine whether the request URL begins with "/", and attackers can obtain relevant information by specifying the URL.
References