VYPR
Low severityNVD Advisory· Published Dec 6, 2022· Updated Apr 23, 2025

DOM-based cross-site scripting (XSS) in teler dashboard

CVE-2022-23466

Description

teler is an real-time intrusion detection and threat alert dashboard. teler prior to version 2.0.0-rc.4 is vulnerable to DOM-based cross-site scripting (XSS) in the teler dashboard. When teler requests messages from the event stream on the /events endpoint, the log data displayed on the dashboard are not sanitized. This only affects authenticated users and can only be exploited based on detected threats if the log contains a DOM scripting payload. This vulnerability has been fixed on version v2.0.0-rc.4. Users are advised to upgrade. There are no known workarounds for this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
teler.appGo
>= 2.0.0-rc, < 2.0.0-rc.42.0.0-rc.4
teler.appGo
>= 2.0.0-dev, < 2.0.0-dev.22.0.0-dev.2
teler.appGo
>= 0.0.0-20220625162531-2289e90590a9, < 0.0.0-20221203202318-20f59eda24200.0.0-20221203202318-20f59eda2420
teler.appGo
>= 1.2.3-0.20220625162531-2289e90590a9, < 1.2.3-0.20221203202318-20f59eda24201.2.3-0.20221203202318-20f59eda2420

Affected products

2

Patches

Vulnerability mechanics

Generated on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

4

News mentions

0

No linked articles in our index yet.