CVE-2023-48901: Tramyardg Autoexpress
Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.
A SQL injection vulnerability in tramyardg Autoexpress version 1.3.0, allows remote unauthenticated attackers to execute arbitrary SQL commands via the parameter "id" within the getPhotosByCarId function call in details.php.
Affected products
- Tramyardg Autoexpress: version 1.3.0 only
Published 2024-03-21. Last modified 2026-06-17.