An issue was discovered in tramyardg autoexpress version 1.3.0, allows unauthenticated remote attackers to escalate privileges, update car data, delete vehicles, and upload car images via authentication bypass in uploadCarImages.php.
Se descubrió un problema en tramyardg autoexpress versión 1.3.0, que permite a atacantes remotos no autenticados escalar privilegios, actualizar datos de automóviles, eliminar vehículos y cargar imágenes de automóviles mediante la omisión de autenticación en uploadCarImages.php.
Tramyardg Autoexpress version 1.3.0 allows for authentication bypass via unauthenticated API access to admin functionality. This could allow a remote anonymous attacker to delete or update vehicles as well as upload images for vehicles.