CVE-2023-48902

CRITICAL

TramyardG AutoExpress <1.3.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An issue was discovered in tramyardg autoexpress version 1.3.0, allows unauthenticated remote attackers to escalate privileges, update car data, delete vehicles, and upload car images via authentication bypass in uploadCarImages.php.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0128
EPSS Percentile 66.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-269
Status published
Products (1)
tramyardg/autoexpress 1.3.0 alpha
Published Mar 21, 2024
Tracked Since Feb 18, 2026