Threat Intel

v0.1

← CVEs

CVE-2019-25454

MED 6.1
Published
2026-02-20
Last Modified
2026-03-02
Affected Apps
12
Affected Devices
25
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
phpMoAdmin 1.1.5 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the collection parameter. Attackers can send GET requests to moadmin.php with script payloads in the collection parameter during collection creation to execute arbitrary JavaScript in users' browsers.
References 3