CVE-2019-25451

phpMoAdmin 1.1.5 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized database operations by crafting malicious requests. Attackers can trick authenticated users into submitting GET requests to moadmin.php with parameters like action, db, and collection to create, drop, or repair databases and collections without user consent.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpmoadmin:phpmoadmin:1.1.5:*:*:*:*:*:*:*

History

02 Mar 2026, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 4.3
v2 : unknown
v3 : 8.8

25 Feb 2026, 15:15

Type Values Removed Values Added
CPE cpe:2.3:a:phpmoadmin:phpmoadmin:1.1.5:*:*:*:*:*:*:*
First Time Phpmoadmin
Phpmoadmin phpmoadmin
References () http://www.phpmoadmin.com/ - () http://www.phpmoadmin.com/ - Product
References () https://www.exploit-db.com/exploits/46082 - () https://www.exploit-db.com/exploits/46082 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/phpmoadmin-cross-site-request-forgery-via-moadminphp - () https://www.vulncheck.com/advisories/phpmoadmin-cross-site-request-forgery-via-moadminphp - Broken Link
Summary
  • (es) PHPMoAdmin 1.1.5 contiene una vulnerabilidad de falsificación de petición en sitios cruzados que permite a los atacantes realizar operaciones de base de datos no autorizadas mediante la creación de peticiones maliciosas. Los atacantes pueden engañar a los usuarios autenticados para que envíen peticiones GET a moadmin.php con parámetros como action, db y collection para crear, eliminar o reparar bases de datos y colecciones sin el consentimiento del usuario.

20 Feb 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-20 23:16

Updated : 2026-03-02 15:16


NVD link : CVE-2019-25451

Mitre link : CVE-2019-25451

CVE.ORG link : CVE-2019-25451


JSON object : View

Products Affected

phpmoadmin

  • phpmoadmin
CWE
CWE-918

Server-Side Request Forgery (SSRF)