phpMoAdmin 1.1.5 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the newdb parameter. Attackers can craft URLs with JavaScript payloads in the newdb parameter of moadmin.php to execute arbitrary code in users' browsers when they visit the malicious link.
References
| Link | Resource |
|---|---|
| http://www.phpmoadmin.com/ | Product |
| https://www.exploit-db.com/exploits/46082 | Exploit VDB Entry |
| https://www.vulncheck.com/advisories/phpmoadmin-reflected-cross-site-scripting-via-moadminphp | Third Party Advisory Broken Link |
Configurations
History
24 Feb 2026, 20:43
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:phpmoadmin:phpmoadmin:1.1.5:*:*:*:*:*:*:* | |
| References | () http://www.phpmoadmin.com/ - Product | |
| References | () https://www.exploit-db.com/exploits/46082 - Exploit, VDB Entry | |
| References | () https://www.vulncheck.com/advisories/phpmoadmin-reflected-cross-site-scripting-via-moadminphp - Third Party Advisory, Broken Link | |
| First Time |
Phpmoadmin
Phpmoadmin phpmoadmin |
20 Feb 2026, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-20 23:16
Updated : 2026-02-24 20:43
NVD link : CVE-2019-25453
Mitre link : CVE-2019-25453
CVE.ORG link : CVE-2019-25453
JSON object : View
Products Affected
phpmoadmin
- phpmoadmin
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
