{"id":"CVE-2022-23466","aliases":["GHSA-xr7p-8q82-878q"],"url":"https://o3.security/vulnerability/CVE-2022-23466","summary":"DOM-based cross-site scripting (XSS) in teler dashboard","details":"### Description\n\nteler prior to version <= 2.0.0-rc.4 is vulnerable to DOM-based cross-site scripting (XSS) in the teler dashboard. When teler requests messages from the event stream on the `/events` endpoint, the log data displayed on the dashboard are not sanitized.\n\n### Impact\n\nThis only affects authenticated users and can only be exploited based on detected threats if the log contains a DOM scripting payload. This indicates a low severity and there is no significant impact on the users.\n\n### Affected Version\n\nThis issue was introduced from version `v2.0.0-rc` to `v2.0.0-rc.3` & `v2.0.0-dev`.\n\n### Patches\n\nThis vulnerability has been fixed on version `v2.0.0-rc.4` & `v2.0.0-dev.2`.\n\n### Workarounds\n\nHere are some workarounds to handle this case:\n- Deactivate the live event dashboard from the configuration file, or\n- Upgrade teler version to `v2.0.0-rc.4` or `v2.0.0-dev.2` & above.\n\n### References\n\n- https://github.com/kitabisa/teler/commit/20f59eda2420ac64e29f199a61230a0abc875e8e","published":"2022-12-06T17:58:52.867Z","modified":"2026-08-27T03:49:38.576420758Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"teler.app","fixedVersion":"2.0.0-rc.4"},{"ecosystem":"Go","name":"teler.app","fixedVersion":"2.0.0-dev.2"},{"ecosystem":"Go","name":"teler.app","fixedVersion":"0.0.0-20221203202318-20f59eda2420"},{"ecosystem":"Go","name":"teler.app","fixedVersion":"1.2.3-0.20221203202318-20f59eda2420"}],"fix":{"url":"https://github.com/kitabisa/teler/commit/20f59eda2420ac64e29f199a61230a0abc875e8e","label":"kitabisa/teler@20f59ed"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23466.json"},{"type":"ADVISORY","url":"https://github.com/kitabisa/teler/security/advisories/GHSA-xr7p-8q82-878q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23466"},{"type":"FIX","url":"https://github.com/kitabisa/teler/commit/20f59eda2420ac64e29f199a61230a0abc875e8e"},{"type":"PACKAGE","url":"https://github.com/kitabisa/teler"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T03:49:38.576420758Z"}}