CVE-2019-25453
MEDIUMphpMoAdmin 1.1.5 - XSS
Title source: llmDescription
phpMoAdmin 1.1.5 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the newdb parameter. Attackers can craft URLs with JavaScript payloads in the newdb parameter of moadmin.php to execute arbitrary code in users' browsers when they visit the malicious link.
Exploits (1)
Scores
CVSS v3
6.1
EPSS
0.0008
EPSS Percentile
22.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
published
Affected Products (1)
phpmoadmin/phpmoadmin
Timeline
Published
Feb 20, 2026
Tracked Since
Feb 21, 2026