Impact
Kepler Wallpaper Script version 1.1 contains a SQL injection flaw in the category parameter, allowing an attacker to inject arbitrary SQL through GET requests. The vulnerability enables extraction of usernames, database names, and MySQL version information, exposing sensitive data and potentially serving as a foothold for further attacks. It corresponds to CWE-89.
Affected Systems
Any deployment of Kepler Wallpapers Script 1.1, the standalone PHP application provided by Keplerwallpapers, is affected. The script is commonly used as a component in web sites that offer wallpaper services.
Risk and Exploitability
The CVSS base score of 8.8 indicates high severity. No EPSS score is available and the vulnerability is not listed in the KEV catalog, so the exploitation likelihood is uncertain but not negligible. The flaw can be triggered by unauthenticated users via a direct HTTP GET request to the category endpoint, making exploitation relatively straightforward for an exposed instance.
OpenCVE Enrichment