SQL Injection Vulnerability in Kados R10 GreenBee by Kados
CVE-2018-25394

8.8HIGH

Key Information:

Vendor

Kados

Vendor
CVE Published:
29 May 2026

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2018-25394?

Kados R10 GreenBee is impacted by an SQL injection vulnerability that permits unauthorized users to execute arbitrary SQL queries. This exploit arises when the release_id parameter is passed to boards_buttons/update_release.php without proper input sanitization. Malicious actors can exploit this vulnerability by crafting a GET request with a UNION-based payload, potentially allowing them to retrieve sensitive database information such as current user data, database names, and the version of the database management system. Proper security measures and coding practices should be implemented to mitigate this risk.

Affected Version(s)

Kados R10 GreenBee R10 GreenBee

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ihsan Sencan
.