CVE-2019-25451

HIGH

phpMoAdmin 1.1.5 - CSRF

Title source: llm
STIX 2.1

Description

phpMoAdmin 1.1.5 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized database operations by crafting malicious requests. Attackers can trick authenticated users into submitting GET requests to moadmin.php with parameters like action, db, and collection to create, drop, or repair databases and collections without user consent.

Exploits (1)

exploitdb WORKING POC
by Ozer Goker · textwebappsphp
https://www.exploit-db.com/exploits/46082

References (3)

Core 3
Core References
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/46082
Various Sources product
http://www.phpmoadmin.com/

Scores

CVSS v3 8.8
EPSS 0.0006
EPSS Percentile 17.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (2)
phpmoadmin/phpmoadmin 1.1.5
Phpmoadmin/phpMoAdmin 1.1.5
Published Feb 20, 2026
Tracked Since Feb 21, 2026