CVE-2019-25454
MEDIUMphpMoAdmin 1.1.5 - Unauthenticated Stored Cross-Site Scripting via Collection Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25454. PoCs published by Ozer Goker.
AI-analyzed exploit summary The exploit demonstrates multiple CSRF and XSS vulnerabilities in phpMoAdmin 1.1.5. It includes functional HTML forms for CSRF attacks and URLs with payloads for reflected and stored XSS.
Description
phpMoAdmin 1.1.5 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the collection parameter. Attackers can send GET requests to moadmin.php with script payloads in the collection parameter during collection creation to execute arbitrary JavaScript in users' browsers.
Exploits (1)
The exploit demonstrates multiple CSRF and XSS vulnerabilities in phpMoAdmin 1.1.5. It includes functional HTML forms for CSRF attacks and URLs with payloads for reflected and stored XSS.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N