ZeroHour

CVE-2023-48903

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p46
Published
()
Modified
Description

Stored Cross-Site Scripting (XSS) vulnerability in tramyardg autoexpress 1.3.0, allows remote unauthenticated attackers to inject arbitrary web script or HTML within parameter "imgType" via in uploadCarImages.php.

Vendors
tramyardg
Products
autoexpress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.