PT-2025-40936 · Phpgurukul · Phpgurukul Hospital Management System
Published
2025-10-06
·
Updated
2025-10-21
·
CVE-2025-28129
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Phpgurukul Hostel Management System version 2.1
Description
The Phpgurukul Hostel Management System version 2.1 is susceptible to clickjacking. This allows an attacker to trick a user into performing actions they did not intend to perform. The system is vulnerable because it does not implement sufficient protections against malicious websites embedding it within an iframe and misleading users.
Recommendations
Apply appropriate anti-clickjacking measures, such as adding the X-Frame-Options header to prevent the system from being embedded in an iframe.
Exploit
Fix
Clickjacking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpgurukul Hospital Management System