These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2018-25395 documents an unauthenticated SQL injection vulnerability in Kados R10 GreenBee, a project management application. The flaw exists in the `feature_id` parameter of `boards_buttons/update_feature.php`, where user-supplied input is concatenated directly into SQL statements without sanitization. Attackers can exploit this via crafted GET requests using UNION-based payloads to extract sensitive [truncated]
CVE-2018-25394 documents an unauthenticated SQL injection vulnerability in Kados R10 GreenBee, a project management application. The flaw exists in the `release_id` parameter of `boards_buttons/update_release.php`, where user-supplied input is concatenated directly into SQL statements without sanitization. Attackers can exploit this via crafted GET requests using UNION-based payloads to extract sensitive [truncated]
CVE-2019-25704 is an SQL injection vulnerability in Kados R10 GreenBee. The vulnerability allows attackers to manipulate database queries by injecting SQL code through the filter_user_mail parameter. This could lead to unauthorized data access or modification. Security teams should review the vulnerability details and prioritize patching to prevent potential data breaches.
CVE-2019-25702 is an SQL injection vulnerability in Kados R10 GreenBee. The vulnerability allows attackers to manipulate database queries by injecting SQL code through the id_project parameter. This type of vulnerability can have significant impacts on the security of the affected system, as it could allow attackers to extract sensitive database information or modify data. Users of Kados R10 GreenBee shou [truncated]
CVE-2019-25698 Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_to_delete parameter. Attackers can send crafted requests with malicious SQL statements in the id_to_delete field to extract or modify sensitive database information. This vulnerability has a high CVSS score of 8.8 and is categorized as HIGH sev [truncated]
CVE-2019-25696 Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the language_tag parameter. Attackers can submit malicious SQL statements in the language_tag parameter to extract sensitive database information or modify data. The vulnerability has a CVSS score of 8.8 and is classified as HIGH severity. This vulner [truncated]
CVE-2019-25694 is an SQL injection vulnerability in Kados R10 GreenBee that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the user2reset parameter. This vulnerability has a high CVSS score of 8.8, indicating a high severity level. Security teams and administrators responsible for Kados R10 GreenBee installations should prioritize patching this vulnerability [truncated]
CVE-2019-25692 Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the 'id_to_modify' parameter. Attackers can send crafted requests with malicious SQL statements in the id_to_modify field to extract sensitive database information or modify data. This vulnerability has a high CVSS score of 8.8, indicating a high seve [truncated]
CVE-2019-25690 is an SQL injection vulnerability in Kados R10 GreenBee, allowing attackers to inject SQL code through the mng_profile_id parameter to extract sensitive database information. This vulnerability has a high CVSS score of 8.8, indicating a high severity level. Security teams and administrators of Kados R10 GreenBee should prioritize patching this vulnerability to prevent potential data breache [truncated]
CVE-2019-25688 Kados R10 GreenBee SQL Injection Vulnerability. The vulnerability allows unauthenticated attackers to manipulate database queries by injecting SQL code through the menu_lev1 parameter. This SQL injection vulnerability in Kados R10 GreenBee can lead to unauthorized access and manipulation of sensitive database information. Security teams should assess the risk and prioritize patching to prev [truncated]