Junglewise Threat Intelligence

CVE-2019-25692: Kados R10 GreenBee SQL injection in id_to_modify parameter

CVE-2019-25692 · Severity: high · CVSS 8.2 · Published 2026-04-05

Technologies: Kados R10 GreenBee. Vendors: Kados.

Executive brief

Kados R10 GreenBee, a web-based project management tool for Scrum and Agile teams, contains a security vulnerability that allows unauthorized access to its database. By sending specially crafted web requests, an attacker can bypass security controls to view sensitive information or modify data within the system. This could lead to the exposure of confidential project details, user credentials, or the unauthorized alteration of project management records.

Technical details

An SQL injection vulnerability exists in Kados R10 GreenBee due to improper neutralization of special elements in the 'id_to_modify' parameter used in database queries. The flaw is reachable via the 'administration/parameters.php' and 'administration/news.php' endpoints. A remote, unauthenticated attacker can exploit this by sending crafted GET requests containing malicious SQL statements. Successful exploitation allows the attacker to extract sensitive information from the database or modify existing records. Public exploit code (PoC) is available, demonstrating both error-based and blind SQL injection techniques across multiple parameters including 'menu_lev1', 'mng_profile_id', and 'user2reset'.

Affected products

  • Kados Kados R10 GreenBee R10 GreenBee

Timeline

  • 2019-03-07: disclosed: Exploit code published on Exploit-DB
  • 2026-04-05: advisory: NVD publication date

References

Related threats