CVE-2019-25453

MEDIUM

phpMoAdmin 1.1.5 - XSS

Title source: llm

Description

phpMoAdmin 1.1.5 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the newdb parameter. Attackers can craft URLs with JavaScript payloads in the newdb parameter of moadmin.php to execute arbitrary code in users' browsers when they visit the malicious link.

Exploits (1)

exploitdb WORKING POC
by Ozer Goker · textwebappsphp
https://www.exploit-db.com/exploits/46082

Scores

CVSS v3 6.1
EPSS 0.0008
EPSS Percentile 22.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Classification

CWE
CWE-79
Status published

Affected Products (1)

phpmoadmin/phpmoadmin

Timeline

Published Feb 20, 2026
Tracked Since Feb 21, 2026