Impact
The vulnerability is an improper neutralization of special elements used in an SQL command, classified as CWE‑89. An attacker can inject arbitrary SQL code into the tPlayer plugin’s queries, potentially reading or manipulating the database. The vulnerability’s CVSS score of 9.3 indicates high severity, with possible confidentiality, integrity, and availability impacts if the database stores critical data or services.
Affected Systems
The affected product is the tPlayer plugin from vendor mmetrodw, version 1.2.1.6 and any earlier releases. No further version details are specified.
Risk and Exploitability
The EPSS score is under 1 %, indicating a low current exploitation probability, and the vulnerability is not listed in CISA KEV. The attack vector is likely an unauthenticated HTTP request to a plugin‑provided endpoint that accepts user input, as no authentication requirement is mentioned. Once exploitation is achieved, the attacker could execute arbitrary SQL statements.
OpenCVE Enrichment