Three high-severity CVEs document SQL injection flaws in Kados R10 GreenBee that can be exploited remotely without privileges or user interaction. The vulnerabilities affect the filter_user_mail parameter (CVE-2019-25704), the id_project parameter (CVE-2019-25702), and the mng_profile_id parameter (CVE-2019-25690), all classified as CWE-89. The issues allow attackers to inject SQL into backend queries, creating a path to read sensitive database contents and, in some cases, alter stored data.
The CVE records include CVSS v3.1 and, for some entries, v4.0 scoring that describes low-complexity network exploitation with no authentication required. Public references tied to the disclosures include Exploit-DB, SourceForge, the Kados website, and a VulnCheck advisory, indicating that technical details and supporting material are available for defenders assessing exposure in GreenBee deployments.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
A CVE entry documented an SQL injection vulnerability in Kados R10 GreenBee affecting boards_buttons/update_feature.php, where the feature_id parameter was concatenated into SQL statements without sanitization. The record said unauthenticated attackers could use a crafted GET request with a UNION-based payload to extract sensitive database information.
Another CVE entry was received for an SQL injection vulnerability in Kados R10 GreenBee affecting the filter_user_mail parameter. The record noted potential extraction of sensitive information or modification of data and included CWE-89 and CVSS scoring details.
A separate CVE record documented an SQL injection flaw in Kados R10 GreenBee through the id_project parameter. The entry indicated attackers could manipulate database queries remotely with low complexity and no required privileges or user interaction.
A CVE record for an SQL injection vulnerability in Kados R10 GreenBee was received by disclosure@vulncheck.com, describing exploitation via the mng_profile_id parameter. The issue was classified as CWE-89 and described as remotely exploitable without privileges or user interaction.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
8 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.