CVE-2025-64387

N/A Unknown
Published: October 31, 2025 Modified: November 04, 2025

Description

The web application is vulnerable to a so-called โ€˜clickjackingโ€™ attack. In this type of attack, the vulnerable page is inserted into a page controlled by the attacker in order to deceive the victim. This deception can range from making the victim click on a button to making them enter their login credentials in a form that, a priori, appears legitimate.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://cds.thalesgroup.com/es/s21sec
Source: 50b5080a-775f-442e-83b5-926b5ca517b6
https://www.hackrtu.com/blog/cg-0day-en-003/
Source: 50b5080a-775f-442e-83b5-926b5ca517b6

3 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
0.1%
18th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)