PT-2025-40936 · Phpgurukul · Phpgurukul Hospital Management System

CVE-2025-28129

·

Published

2025-10-06

·

Updated

2025-10-21

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Phpgurukul Hostel Management System version 2.1
Description The Phpgurukul Hostel Management System version 2.1 is susceptible to clickjacking. This allows an attacker to trick a user into performing actions they did not intend to perform. The system is vulnerable because it does not implement sufficient protections against malicious websites embedding it within an iframe and misleading users.
Recommendations Apply appropriate anti-clickjacking measures, such as adding the X-Frame-Options header to prevent the system from being embedded in an iframe.

Exploit

Fix

Clickjacking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-28129

Affected Products

Phpgurukul Hospital Management System