Executive brief
Kados R10 GreenBee, a web-based project management tool for Scrum and Agile teams, contains a security vulnerability that allows attackers to interfere with its database. By sending specially crafted requests, an unauthorized user could view sensitive information or modify data within the system. This could lead to the exposure of confidential project details or the unauthorized alteration of project records.
Technical details
A SQL injection vulnerability exists in Kados R10 GreenBee due to improper neutralization of special elements in the 'language_tag' parameter (and others including 'menu_lev1', 'mng_profile_id', 'id_to_modify', and 'user2reset'). An unauthenticated remote attacker can exploit this by sending crafted GET requests to various PHP endpoints such as languages.php or users.php. Successful exploitation allows for unauthorized data extraction via error-based or blind SQL injection techniques, and potentially data modification. While the advisory specifically highlights 'language_tag', public exploit code demonstrates the vulnerability across multiple parameters in the R10 GreenBee version.
Affected products
- Kados Kados R10 GreenBee R10 GreenBee
Timeline
- 2019-03-07: disclosed: Exploit code published on Exploit-DB
- 2019-12-22: patched: Version R11-YellowCat released which may address technical issues
- 2026-04-05: advisory: CVE-2019-25696 published in NVD