Impact
The flaw is a classic SQL injection vulnerability (CWE-89) in the AcyMailing extension for Joomla, affecting all releases prior to version 10.11.1. By submitting crafted input, a malicious actor can inject arbitrary SQL statements that are executed against the site’s database, allowing read, modification or deletion of sensitive data. The high CVSS score of 9.2 underlines the severity of the impact if the flaw is exploited.
Affected Systems
All installations of the AcyMailing extension for Joomla supplied by acymailing.com that are running a version earlier than 10.11.1 are vulnerable. No other vendors or product versions are explicitly listed as affected in the CVE data.
Risk and Exploitability
The CVSS score of 9.2 indicates a critical threat level, while the EPSS score of less than 1% suggests that active exploitation is unlikely but still possible. The vulnerability is listed outside of CISA’s Known Exploited Vulnerabilities catalog, which does not lower its perceived risk. Based on the description, the likely attack vector is remote, via the web interface where unfiltered input is processed by the AcyMailing component, and an attacker who can access this route could obtain full database read capabilities or modify data.
OpenCVE Enrichment