NA

CVE-2023-48901

Published: 21/03/2024 Updated: 21/03/2024

Vulnerability Summary

A SQL injection vulnerability in tramyardg Autoexpress version 1.3.0, allows remote unauthenticated malicious users to execute arbitrary SQL commands via the parameter "id" within the getPhotosByCarId function call in details.php.

Exploits

Tramyardg Autoexpress version 130 suffers from a remote SQL injection vulnerability ...