RULE(RULE ID:333370)

Rule General Information
Release Date: 2021-04-01
Rule Name: Joomla Component CcNewsletter SQL Injection Vulnerability (CVE-2018-5989)
Severity:
CVE ID:
Rule Protection Details
Description: SQL Injection exists in the ccNewsletter 2.x component for Joomla! via the id parameter in a task=removeSubscriber action, a related issue to CVE-2011-5099.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference: https://exploit-db.com/exploits/44132
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://www.chillcreations.com/