CVE-2019-25453

MEDIUM

phpMoAdmin 1.1.5 - XSS

Title source: llm
STIX 2.1

Description

phpMoAdmin 1.1.5 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the newdb parameter. Attackers can craft URLs with JavaScript payloads in the newdb parameter of moadmin.php to execute arbitrary code in users' browsers when they visit the malicious link.

Exploits (1)

exploitdb WORKING POC
by Ozer Goker · textwebappsphp
https://www.exploit-db.com/exploits/46082

References (3)

Core 3
Core References
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/46082
Various Sources product
http://www.phpmoadmin.com/

Scores

CVSS v3 6.1
EPSS 0.0013
EPSS Percentile 32.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
phpmoadmin/phpmoadmin 1.1.5
Phpmoadmin/phpMoAdmin 1.1.5
Published Feb 20, 2026
Tracked Since Feb 21, 2026