SQL Injection Vulnerability in Kados R10 GreenBee by Kados
CVE-2018-25394
8.8HIGH
What is CVE-2018-25394?
Kados R10 GreenBee is impacted by an SQL injection vulnerability that permits unauthorized users to execute arbitrary SQL queries. This exploit arises when the release_id parameter is passed to boards_buttons/update_release.php without proper input sanitization. Malicious actors can exploit this vulnerability by crafting a GET request with a UNION-based payload, potentially allowing them to retrieve sensitive database information such as current user data, database names, and the version of the database management system. Proper security measures and coding practices should be implemented to mitigate this risk.
Affected Version(s)
Kados R10 GreenBee R10 GreenBee
References
CVSS V4
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Ihsan Sencan
