Junglewise Threat Intelligence

CVE-2019-25696: Kados R10 GreenBee SQL injection in language_tag parameter

CVE-2019-25696 · Severity: high · CVSS 8.2 · Published 2026-04-05

Technologies: Kados R10 GreenBee. Vendors: Kados.

Executive brief

Kados R10 GreenBee, a web-based project management tool for Scrum and Agile teams, contains a security vulnerability that allows attackers to interfere with its database. By sending specially crafted requests, an unauthorized user could view sensitive information or modify data within the system. This could lead to the exposure of confidential project details or the unauthorized alteration of project records.

Technical details

A SQL injection vulnerability exists in Kados R10 GreenBee due to improper neutralization of special elements in the 'language_tag' parameter (and others including 'menu_lev1', 'mng_profile_id', 'id_to_modify', and 'user2reset'). An unauthenticated remote attacker can exploit this by sending crafted GET requests to various PHP endpoints such as languages.php or users.php. Successful exploitation allows for unauthorized data extraction via error-based or blind SQL injection techniques, and potentially data modification. While the advisory specifically highlights 'language_tag', public exploit code demonstrates the vulnerability across multiple parameters in the R10 GreenBee version.

Affected products

  • Kados Kados R10 GreenBee R10 GreenBee

Timeline

  • 2019-03-07: disclosed: Exploit code published on Exploit-DB
  • 2019-12-22: patched: Version R11-YellowCat released which may address technical issues
  • 2026-04-05: advisory: CVE-2019-25696 published in NVD

References

Related threats