CVE-2019-25690: Marmotech Kados
High severity, CVSS 8.2. EPSS: 0.3% chance of exploitation in the next 30 days.
Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the mng_profile_id parameter. Attackers can send crafted requests with malicious SQL payloads in the mng_profile_id parameter to extract sensitive database information.
Affected products
- Marmotech Kados: version r10_greenbee only
Published 2026-04-05. Last modified 2026-07-24.