SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHoverText, or getPathDetails request.
View the template here CVE-2018-6605.yaml
References:
https://nvd.nist.gov/vuln/detail/CVE-2018-6605