A bug has been discovered in the "Front End News Submitter" (fe_news) where SQL injection is not safely prevented and thus malicious SQL commands are potentially possible.
Since the RTE enabled version (fe_rtenews) is derived from fe_news, it is affected as well.