CVE-2019-25451 PUBLISHED

phpMoAdmin 1.1.5 Cross-Site Request Forgery via moadmin.php

Assigner: VulnCheck
Reserved: 20.02.2026 Published: 20.02.2026 Updated: 20.02.2026

phpMoAdmin 1.1.5 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized database operations by crafting malicious requests. Attackers can trick authenticated users into submitting GET requests to moadmin.php with parameters like action, db, and collection to create, drop, or repair databases and collections without user consent.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L
CVSS Score: 5.3

Product Status

Vendor Phpmoadmin
Product phpMoAdmin
Versions
  • Version 1.1.5 is affected

Credits

  • Ozer Goker finder

References

Problem Types

  • Server-Side Request Forgery (SSRF) CWE