Executive brief
Kados GreenBee, a web-based project management tool for Scrum and Agile teams, contains a security flaw that allows unauthorized users to interfere with its database. By sending specially crafted web requests, an attacker can bypass security controls to view sensitive project data or modify database records. This could lead to the exposure of confidential business information or the disruption of project management operations.
Technical details
An SQL injection vulnerability exists in Kados R10 GreenBee due to improper neutralization of special elements in the 'menu_lev1' parameter across multiple PHP files (e.g., projects.php, users.php, profiles.php). An unauthenticated remote attacker can exploit this by sending crafted GET requests containing malicious SQL payloads. Successful exploitation allows the attacker to extract sensitive information from the database or modify its contents. Additional vulnerable parameters identified in the same version include 'mng_profile_id', 'id_to_modify', 'user2reset', and 'language_tag'. While a newer version (R11-YellowCat) was released in late 2019, users should verify if these specific flaws are addressed or migrate to the latest supported version.
Affected products
- Kados Kados GreenBee R10 GreenBee
Timeline
- 2019-03-07: disclosed: Initial exploit code published on Exploit-DB
- 2019-12-22: other: Newer version R11-YellowCat released
- 2026-04-05: advisory: CVE-2019-25688 published