CVE-2023-48901

A SQL injection vulnerability in tramyardg Autoexpress version 1.3.0, allows remote unauthenticated attackers to execute arbitrary SQL commands via the parameter "id" within the getPhotosByCarId function call in details.php.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:tramyardg:autoexpress:1.3.0:alpha:*:*:*:*:*:*

History

19 May 2025, 13:06

Type Values Removed Values Added
References () https://packetstormsecurity.com/files/177660/Tramyardg-Autoexpress-1.3.0-SQL-Injection.html - () https://packetstormsecurity.com/files/177660/Tramyardg-Autoexpress-1.3.0-SQL-Injection.html - Exploit, Third Party Advisory
First Time Tramyardg
Tramyardg autoexpress
CPE cpe:2.3:a:tramyardg:autoexpress:1.3.0:alpha:*:*:*:*:*:*

21 Mar 2024, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-21 04:15

Updated : 2025-05-19 13:06


NVD link : CVE-2023-48901

Mitre link : CVE-2023-48901


JSON object : View

Products Affected

tramyardg

  • autoexpress
CWE

No CWE.