Filtered by vendor Phpmoadmin Subscriptions
Filtered by product Phpmoadmin Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2019-25451 1 Phpmoadmin 1 Phpmoadmin 2026-02-23 4.3 Medium
phpMoAdmin 1.1.5 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized database operations by crafting malicious requests. Attackers can trick authenticated users into submitting GET requests to moadmin.php with parameters like action, db, and collection to create, drop, or repair databases and collections without user consent.
CVE-2019-25453 1 Phpmoadmin 1 Phpmoadmin 2026-02-23 6.1 Medium
phpMoAdmin 1.1.5 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the newdb parameter. Attackers can craft URLs with JavaScript payloads in the newdb parameter of moadmin.php to execute arbitrary code in users' browsers when they visit the malicious link.
CVE-2019-25454 1 Phpmoadmin 1 Phpmoadmin 2026-02-23 7.2 High
phpMoAdmin 1.1.5 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the collection parameter. Attackers can send GET requests to moadmin.php with script payloads in the collection parameter during collection creation to execute arbitrary JavaScript in users' browsers.