phpMoAdmin 1.1.5 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized database operations by crafting malicious requests. Attackers can trick authenticated users into submitting GET requests to moadmin.php with parameters like action, db, and collection to create, drop, or repair databases and collections without user consent.
Metrics
Affected Vendors & Products
References
History
Fri, 20 Feb 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | phpMoAdmin 1.1.5 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized database operations by crafting malicious requests. Attackers can trick authenticated users into submitting GET requests to moadmin.php with parameters like action, db, and collection to create, drop, or repair databases and collections without user consent. | |
| Title | phpMoAdmin 1.1.5 Cross-Site Request Forgery via moadmin.php | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-02-20T22:57:00.942Z
Updated: 2026-02-20T22:57:00.942Z
Reserved: 2026-02-20T18:37:32.015Z
Link: CVE-2019-25451
No data.
Status : Received
Published: 2026-02-20T23:16:01.713
Modified: 2026-02-20T23:16:01.713
Link: CVE-2019-25451
No data.