### [CVE-2022-23051](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23051) ![](https://img.shields.io/static/v1?label=Product&message=PeTeReport&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Stored%20cross-site%20scripting%20(XSS)&color=brighgreen) ### Description PeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code while adding an 'Attack Tree' by modifying the 'svg_file' parameter. ### POC #### Reference - https://fluidattacks.com/advisories/brown/ #### Github No PoCs found on GitHub currently.