Mend.io Vulnerability Database
The largest open source vulnerability database
What is a Vulnerability ID?
New vulnerability? Tell us about it!
CVE-2022-23466
December 06, 2022
teler is an real-time intrusion detection and threat alert dashboard. teler prior to version 2.0.0-rc.4 is vulnerable to DOM-based cross-site scripting (XSS) in the teler dashboard. When teler requests messages from the event stream on the "/events" endpoint, the log data displayed on the dashboard are not sanitized. This only affects authenticated users and can only be exploited based on detected threats if the log contains a DOM scripting payload. This vulnerability has been fixed on version "v2.0.0-rc.4". Users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Packages
teler.app (GO):
Affected version(s) >=v1.2.3-0.20220625162531-2289e90590a9 <v1.2.3-0.20221203202318-20f59eda2420
Fix Suggestion:
Update to version v1.2.3-0.20221203202318-20f59eda2420
teler.app (GO):
Affected version(s) =v0.0.0-20220625162531-2289e90590a9 <v0.0.0-20221203202318-20f59eda2420
Fix Suggestion:
Update to version v0.0.0-20221203202318-20f59eda2420
Additional Notes
The description of this vulnerability differs from MITRE.
Do you need more information?
Contact Us
CVSS v4
Base Score:
5.3
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
PASSIVE
Vulnerable System Confidentiality
LOW
Vulnerable System Integrity
LOW
Vulnerable System Availability
NONE
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
5.4
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE
Weakness Type (CWE)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
EPSS
Base Score:
0.21