{"id":"CVE-2022-23466","summary":"DOM-based cross-site scripting (XSS) in teler dashboard","details":"teler is an real-time intrusion detection and threat alert dashboard. teler prior to version 2.0.0-rc.4 is vulnerable to DOM-based cross-site scripting (XSS) in the teler dashboard. When teler requests messages from the event stream on the `/events` endpoint, the log data displayed on the dashboard are not sanitized. This only affects authenticated users and can only be exploited based on detected threats if the log contains a DOM scripting payload. This vulnerability has been fixed on version `v2.0.0-rc.4`. Users are advised to upgrade. There are no known workarounds for this vulnerability.","aliases":["GHSA-xr7p-8q82-878q"],"modified":"2026-05-28T03:55:42.225985288Z","published":"2022-12-06T17:58:52.867Z","database_specific":{"cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23466.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23466.json"},{"type":"ADVISORY","url":"https://github.com/kitabisa/teler/security/advisories/GHSA-xr7p-8q82-878q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23466"},{"type":"FIX","url":"https://github.com/kitabisa/teler/commit/20f59eda2420ac64e29f199a61230a0abc875e8e"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/teler-sh/teler","events":[{"introduced":"a48ac198ff94ebe75d8f7d5f339ce4900fc60b07"},{"fixed":"67e26f486d85e294a6ecff822d236c04787b316e"}]}],"versions":["v2.0.0-dev","v2.0.0-rc.3","v2.0.0-rc.2","v2.0.0-rc"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-23466.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"}]}