Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
5.1
phpMoAdmin: Unauthenticated Attackers Can Inject Malicious Scripts
CVE-2019-25453
Summary
A security issue in phpMoAdmin allows attackers to inject malicious scripts into users' browsers if they visit a specially crafted link. This can happen without needing a password, making it a risk for anyone using phpMoAdmin. Update to the latest version to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| phpmoadmin | phpmoadmin | 1.1.5 | – |
Original title
phpMoAdmin 1.1.5 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the newdb parameter. Attackers can craft U...
Original description
phpMoAdmin 1.1.5 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the newdb parameter. Attackers can craft URLs with JavaScript payloads in the newdb parameter of moadmin.php to execute arbitrary code in users' browsers when they visit the malicious link.
nvd CVSS3.1
6.1
nvd CVSS4.0
5.1
Vulnerability type
CWE-79
Cross-site Scripting (XSS)
- http://www.phpmoadmin.com/ Product
- https://www.exploit-db.com/exploits/46082 Exploit VDB Entry
- https://www.vulncheck.com/advisories/phpmoadmin-reflected-cross-site-scripting-v... Third Party Advisory Broken Link
Published: 20 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026