


Perceptive Security
SOC/SIEM Consultancy

Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code th…
Published:
28 mei 2026 om 22:00:00
Alert date:
29 mei 2026 om 17:11:07
Source:
nvd.nist.gov
Web Technologies, Database & Storage
Kados R10 GreenBee contains an SQL injection vulnerability in the release_id parameter of boards_buttons/update_release.php. The vulnerability allows unauthenticated attackers to execute arbitrary SQL queries through direct concatenation without sanitization. Attackers can exploit this using crafted GET requests with UNION-based payloads. The vulnerability enables extraction of sensitive database information including current user, database name, and DBMS version. This represents a critical security flaw affecting the Kados R10 GreenBee application.
Technical details
Mitigation steps:
Affected products:
Kados R10 GreenBee
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2018-25394
https://sourceforge.net/projects/kados/
https://www.exploit-db.com/exploits/45617
https://www.kados.info/
https://www.vulncheck.com/advisories/kados-r10-greenbee-sql-injection-via-update-release-php
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
