CVE-2019-25451
Severity CVSS v4.0:
MEDIUM
Type:
CWE-918
Server-Side Request Forgery (SSRF)
Publication date:
20/02/2026
Last modified:
02/03/2026
Description
phpMoAdmin 1.1.5 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized database operations by crafting malicious requests. Attackers can trick authenticated users into submitting GET requests to moadmin.php with parameters like action, db, and collection to create, drop, or repair databases and collections without user consent.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:phpmoadmin:phpmoadmin:1.1.5:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



