CVE detail
CVE-2019-25451 — CVE-2019-25451
Published 2026-02-20 · Modified 2026-06-17 · Vendor phpmoadmin · Product phpmoadmin · Source nvd
HIGH
severity
CVSS-derived band
0.0032
EPSS probability
exploitation probability, 30d
24.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
phpMoAdmin 1.1.5 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized database operations by crafting malicious requests. Attackers can trick authenticated users into submitting GET requests to moadmin.php with parameters like action, db, and collection to create, drop, or repair databases and collections without user consent.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References