CVE-2025-64387
Description
The web application is vulnerable to a so-called ‘clickjacking’ attack. In this type of attack, the vulnerable page is inserted into a page controlled by the attacker in order to deceive the victim. This deception can range from making the victim click on a button to making them enter their login credentials in a form that, a priori, appears legitimate.
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2025-64387? +
How do I check if I'm vulnerable to CVE-2025-64387? +
Related Vulnerabilities
A Clickjacking vulnerability in TP-Link Archer C1200 web management page allows an attacker to trick users into performing unintended actions …
Cross-Frame Scripting (XFS) vulnerability in BoomCMS v9.1.4 from UXB London. XFS is a web attack technique that exploits specific browser …
Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open …
LB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability via the Administrator login page. Attackers can cause victim users …
A select option could partially obscure security prompts. This could be used by a malicious site to trick a user …
Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to users unknowingly …