CVE-2019-25702

Severity CVSS v4.0:
HIGH
Type:
CWE-89 SQL Injection
Publication date:
05/04/2026
Last modified:
07/04/2026

Description

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_project parameter. Attackers can send crafted requests with malicious SQL statements in the id_project parameter to extract sensitive database information or modify data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:marmotech:kados:r10_greenbee:*:*:*:*:*:*:*