PT-2025-40936 · Phpgurukul · Phpgurukul Hospital Management System

Published

2025-10-06

·

Updated

2025-10-21

·

CVE-2025-28129

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Phpgurukul Hostel Management System version 2.1
Description The Phpgurukul Hostel Management System version 2.1 is susceptible to clickjacking. This allows an attacker to trick a user into performing actions they did not intend to perform. The system is vulnerable because it does not implement sufficient protections against malicious websites embedding it within an iframe and misleading users.
Recommendations Apply appropriate anti-clickjacking measures, such as adding the X-Frame-Options header to prevent the system from being embedded in an iframe.

Exploit

Fix

Clickjacking

Weakness Enumeration

Related Identifiers

CVE-2025-28129

Affected Products

Phpgurukul Hospital Management System