CVE-2023-48901: Tramyardg Autoexpress

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

A SQL injection vulnerability in tramyardg Autoexpress version 1.3.0, allows remote unauthenticated attackers to execute arbitrary SQL commands via the parameter "id" within the getPhotosByCarId function call in details.php.

Affected products

Published 2024-03-21. Last modified 2026-06-17.