CVE-2018-25395

HIGH

Kados R10 GreenBee SQL Injection via update_feature.php

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-25395. PoCs published by Ihsan Sencan.

AI-analyzed exploit summary The exploit demonstrates SQL injection vulnerabilities in Kados R10 GreenBee via the 'release_id' and 'feature_id' parameters. It includes URL-encoded SQL payloads that concatenate malicious queries to extract database information.

Description

Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the feature_id parameter of boards_buttons/update_feature.php. The feature_id value is concatenated directly into SQL statements without sanitization, allowing attackers to send a crafted GET request with a UNION-based payload to extract sensitive database information including the current user, database name, and DBMS version.

Exploits (1)

exploitdb WORKING POC
by Ihsan Sencan · textwebappsphp
https://www.exploit-db.com/exploits/45617

The exploit demonstrates SQL injection vulnerabilities in Kados R10 GreenBee via the 'release_id' and 'feature_id' parameters. It includes URL-encoded SQL payloads that concatenate malicious queries to extract database information.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Kados R10 GreenBee
No auth needed
Prerequisites: Access to the vulnerable endpoint
devstral-2 · analyzed May 29, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-45617
https://www.exploit-db.com/exploits/45617
Product product
Official Product Homepage
https://www.kados.info/
Product product
Product Reference
https://sourceforge.net/projects/kados/
Third Party Advisory third-party-advisory
VulnCheck Advisory: Kados R10 GreenBee SQL Injection via update_feature.php
https://www.vulncheck.com/advisories/kados-r10-greenbee-sql-injection-via-update-feature-php

Scores

CVSS v3 8.2
EPSS 0.0033
EPSS Percentile 25.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
Kados/Kados R10 GreenBee R10 GreenBee
Published May 29, 2026
Tracked Since May 29, 2026