ZeroHour

CVE-2023-48901

PoC
CVSS 3.1
9.8 critical
EPSS
1%p62
Published
()
Modified
Description

A SQL injection vulnerability in tramyardg Autoexpress version 1.3.0, allows remote unauthenticated attackers to execute arbitrary SQL commands via the parameter "id" within the getPhotosByCarId function call in details.php.

Vendors
tramyardg
Products
autoexpress
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.