{"id":"CVE-2022-23466","summary":"DOM-based cross-site scripting (XSS) in teler dashboard","details":"teler is an real-time intrusion detection and threat alert dashboard. teler prior to version 2.0.0-rc.4 is vulnerable to DOM-based cross-site scripting (XSS) in the teler dashboard. When teler requests messages from the event stream on the `/events` endpoint, the log data displayed on the dashboard are not sanitized. This only affects authenticated users and can only be exploited based on detected threats if the log contains a DOM scripting payload. This vulnerability has been fixed on version `v2.0.0-rc.4`. Users are advised to upgrade. There are no known workarounds for this vulnerability.","aliases":["GHSA-xr7p-8q82-878q"],"modified":"2026-04-10T04:44:45.405119Z","published":"2022-12-06T17:58:52.867Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23466.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23466.json"},{"type":"ADVISORY","url":"https://github.com/kitabisa/teler/security/advisories/GHSA-xr7p-8q82-878q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23466"},{"type":"FIX","url":"https://github.com/kitabisa/teler/commit/20f59eda2420ac64e29f199a61230a0abc875e8e"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/kitabisa/teler","events":[{"introduced":"a48ac198ff94ebe75d8f7d5f339ce4900fc60b07"},{"fixed":"67e26f486d85e294a6ecff822d236c04787b316e"}],"database_specific":{"versions":[{"introduced":"v2.0.0-rc"},{"fixed":"v2.0.0-rc.4"}]}},{"type":"GIT","repo":"https://github.com/kitabisa/teler","events":[{"introduced":"0"},{"last_affected":"dfdc7d3318074235b43fba30eb05eecbddd911c9"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"= v2.0.0-dev"}]}}],"versions":["v0.0.1","v0.0.1-beta1","v0.0.1-beta1.2","v0.0.1-beta3","v0.0.1-beta3.1","v0.0.1-beta3.2","v0.0.1-beta4","v0.0.1-dev.4","v0.0.1-dev.4.1","v0.0.1-dev.4.2","v0.0.1-dev.4.3","v0.0.1-dev5","v0.0.1-dev5.1","v0.0.1-rc1.3","v0.0.1-rc2","v0.0.1-rc2.1","v0.0.2","v0.0.3","v0.0.4","v1.0.0","v1.0.0-rc","v1.0.1","v1.0.2","v1.0.3","v1.1.0","v1.1.1","v1.2.0","v1.2.1","v1.2.2","v2.0.0-beta","v2.0.0-beta2","v2.0.0-dev","v2.0.0-rc","v2.0.0-rc.2","v2.0.0-rc.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23466.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/teler-sh/teler","events":[{"introduced":"0"},{"fixed":"20f59eda2420ac64e29f199a61230a0abc875e8e"}]}],"versions":["v0.0.1","v0.0.1-beta1","v0.0.1-beta1.2","v0.0.1-beta3","v0.0.1-beta3.1","v0.0.1-beta3.2","v0.0.1-beta4","v0.0.1-dev.4","v0.0.1-dev.4.1","v0.0.1-dev.4.2","v0.0.1-dev.4.3","v0.0.1-dev5","v0.0.1-dev5.1","v0.0.1-rc1.3","v0.0.1-rc2","v0.0.1-rc2.1","v0.0.2","v0.0.3","v0.0.4","v1.0.0","v1.0.0-rc","v1.0.1","v1.0.2","v1.0.3","v1.1.0","v1.1.1","v1.2.0","v1.2.1","v1.2.2","v2.0.0-beta","v2.0.0-beta2","v2.0.0-dev","v2.0.0-rc","v2.0.0-rc.2","v2.0.0-rc.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23466.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"}]}