A vulnerability marked as critical has been reported in Kados R10 GreenBee. The affected element is an unknown function of the component Request Handler. This manipulation of the argument filter_user_mail causes sql injection.

This vulnerability is handled as CVE-2019-25704. The attack can be initiated remotely. Additionally, an exploit exists.