CVE-2019-25690

HIGH

Kados R10 GreenBee SQL Injection via mng_profile_id

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-25690. PoCs published by Mehmet EMIROGLU.

AI-analyzed exploit summary The exploit demonstrates multiple SQL injection vulnerabilities in Kados R10 GreenBee, targeting parameters like 'menu_lev1', 'mng_profile_id', and others. It includes specific attack patterns and GET request examples to exploit these vulnerabilities.

Description

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the mng_profile_id parameter. Attackers can send crafted requests with malicious SQL payloads in the mng_profile_id parameter to extract sensitive database information.

Exploits (1)

exploitdb WORKING POC
by Mehmet EMIROGLU · textwebappsphp
https://www.exploit-db.com/exploits/46505

The exploit demonstrates multiple SQL injection vulnerabilities in Kados R10 GreenBee, targeting parameters like 'menu_lev1', 'mng_profile_id', and others. It includes specific attack patterns and GET request examples to exploit these vulnerabilities.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Kados R10 GreenBee
No auth needed
Prerequisites: access to the vulnerable web application
devstral-2 · analyzed Apr 07, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-46505
https://www.exploit-db.com/exploits/46505
Product product
Official Product Homepage
https://www.kados.info/
Product product
Product Reference
https://sourceforge.net/projects/kados/
Third Party Advisory third-party-advisory
VulnCheck Advisory: Kados R10 GreenBee SQL Injection via mng_profile_id
https://www.vulncheck.com/advisories/kados-r10-greenbee-sql-injection-via-mng-profile-id

Scores

CVSS v3 8.2
EPSS 0.0031
EPSS Percentile 22.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (2)
Kados/Kados R10 GreenBee R10 GreenBee
marmotech/kados r10_greenbee
Published Apr 05, 2026
Tracked Since Apr 06, 2026