CVE-2019-25451 MEDIUM

CVE-2019-25451: phpMoAdmin 1.1.5 Cross-Site Request Forgery via moadmin.php

Vendor Phpmoadmin
Product phpMoAdmin
Weakness CWE-918 · SSRF
Published February 20, 2026
Last update April 7, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L

What the vulnerability does

01Description

phpMoAdmin 1.1.5 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized database operations by crafting malicious requests. Attackers can trick authenticated users into submitting GET requests to moadmin.php with parameters like action, db, and collection to create, drop, or repair databases and collections without user consent.

Key dates

02Disclosure timeline

February 20, 2026 CVE published
April 7, 2026 Record updated