Vulnerability Details CVE-2023-48903
Stored Cross-Site Scripting (XSS) vulnerability in tramyardg autoexpress 1.3.0, allows remote unauthenticated attackers to inject arbitrary web script or HTML within parameter "imgType" via in uploadCarImages.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 40.7%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2023-48903
-
cpe:2.3:a:tramyardg:autoexpress:1.3.0