CVE-2023-48903: Tramyardg Autoexpress
Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.
Stored Cross-Site Scripting (XSS) vulnerability in tramyardg autoexpress 1.3.0, allows remote unauthenticated attackers to inject arbitrary web script or HTML within parameter "imgType" via in uploadCarImages.php.
Affected products
- Tramyardg Autoexpress: version 1.3.0 only
Published 2024-03-21. Last modified 2026-06-17.