CVE-2019-25700

Severity CVSS v4.0:
HIGH
Type:
CWE-89 SQL Injection
Publication date:
05/04/2026
Last modified:
07/04/2026

Description

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the sort_direction parameter. Attackers can submit malicious SQL statements in the sort_direction parameter to extract sensitive database information or modify data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:marmotech:kados:r10_greenbee:*:*:*:*:*:*:*