Executive brief
Kados R10 GreenBee, a web-based tool for managing Scrum and Agile projects, contains a security vulnerability that allows unauthorized individuals to interfere with its database. By sending specially crafted web requests, an attacker can view sensitive information or modify data within the system. This could lead to the exposure of project management data or unauthorized changes to project tasks and user profiles.
Technical details
An SQL injection vulnerability exists in Kados R10 GreenBee due to improper neutralization of special elements in several parameters, most notably 'filter_user_mail', 'menu_lev1', 'mng_profile_id', and 'id_to_modify'. The flaw is reachable via unauthenticated or low-privileged GET requests to various PHP endpoints including projects.php and users.php. An attacker can exploit this to perform out-of-band data extraction, error-based SQL injection, or time-based blind SQL injection. This allows for the unauthorized retrieval of sensitive database contents or the modification of existing records. While the vulnerability was identified in 2019, it was formally assigned a CVE in 2026; users should upgrade to a supported version such as R11-YellowCat or later.
Affected products
- Kados Kados R10 GreenBee R10 GreenBee
Timeline
- 2019-03-07: disclosed: Exploit code published on Exploit-DB
- 2019-12-22: patched: New version R11-YellowCat released
- 2026-04-05: advisory: CVE-2019-25704 published