Executive brief
Kados R10 GreenBee is a web-based project management tool used for Scrum and Agile workflows. A security vulnerability allows unauthenticated attackers to interfere with the application's database by sending specially crafted web requests. This could lead to the unauthorized exposure of sensitive project data or the modification of information within the system.
Technical details
An SQL injection vulnerability exists in Kados R10 GreenBee due to improper neutralization of special elements in the 'user2reset' parameter within the password reset functionality. An unauthenticated remote attacker can exploit this by sending crafted GET requests containing malicious SQL payloads. Successful exploitation allows for blind SQL injection, enabling the attacker to extract sensitive information from the database or modify data. Other parameters such as 'menu_lev1', 'mng_profile_id', and 'id_to_modify' are also reportedly affected by similar injection flaws. While a newer version (R11-YellowCat) was released in late 2019, users should verify if these specific flaws are addressed or migrate to the latest supported version.
Affected products
- Kados Kados R10 GreenBee R10 GreenBee
Timeline
- 2019-03-07: disclosed: Exploit details published on Exploit-DB
- 2019-12-22: other: Release of R11-YellowCat version
- 2026-04-05: advisory: CVE-2019-25694 published to NVD