CVE-2019-25451

p

hpMoAdmin 1.1.5 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized database operations by crafting malicious requests. Attackers can trick authenticated users into submitting GET requests to moadmin.php with parameters like action, db, and collection to create, drop, or repair databases and collections without user consent.

Configurations

Configuration 1 (hide)

cpe:2.3:a:phpmoadmin:phpmoadmin:1.1.5:*:*:*:*:*:*:*

History

02 Mar 2026, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 4.3
v2 : unknown
v3 : 8.8

25 Feb 2026, 15:15

Type Values Removed Values Added
First Time Phpmoadmin phpmoadmin
Phpmoadmin
Summary
  • (es) PHPMoAdmin 1.1.5 contiene una vulnerabilidad de falsificación de petición en sitios cruzados que permite a los atacantes realizar operaciones de base de datos no autorizadas mediante la creación de peticiones maliciosas. Los atacantes pueden engañar a los usuarios autenticados para que envíen peticiones GET a moadmin.php con parámetros como action, db y collection para crear, eliminar o reparar bases de datos y colecciones sin el consentimiento del usuario.
CPE cpe:2.3:a:phpmoadmin:phpmoadmin:1.1.5:*:*:*:*:*:*:*
References () http://www.phpmoadmin.com/ - () http://www.phpmoadmin.com/ - Product
References () https://www.exploit-db.com/exploits/46082 - () https://www.exploit-db.com/exploits/46082 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/phpmoadmin-cross-site-request-forgery-via-moadminphp - () https://www.vulncheck.com/advisories/phpmoadmin-cross-site-request-forgery-via-moadminphp - Broken Link

20 Feb 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-20 23:16

Updated : 2026-03-02 15:16


NVD link : CVE-2019-25451

Mitre link : CVE-2019-25451

CVE.ORG link : CVE-2019-25451


JSON object : View

Products Affected
CWE
CWE-918

Server-Side Request Forgery (SSRF)