PoC Index

CVE-2023-48901

CRITICAL 9.8EPSS 1.0%

A SQL injection vulnerability in tramyardg Autoexpress version 1.3.0, allows remote unauthenticated attackers to execute arbitrary SQL commands via the parameter "id" within the getPhotosByCarId function call in details.php.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
1.03% chance of exploitation in the next 30 days, 61th percentile
Published
2024-03-21
Updated
2024-08-06

Proof-of-concept exploits (1)

References

Related