Executive brief
A security vulnerability exists in the Akpali9 Attendance-Management-System, a software tool used for tracking employee or student attendance. An attacker could exploit this flaw to inject malicious scripts into the web interface, potentially leading to unauthorized actions being performed in the context of a legitimate user's session. This could compromise the integrity of attendance records or allow for the theft of session information if a user interacts with a malicious link.
Technical details
A cross-site scripting (XSS) vulnerability exists in Akpali9 Attendance-Management-System up to commit 70b91fe38f4195b701a45f0edcd4f42d5f64aeee. The vulnerability is located in the file 'absent.php' and is triggered by insufficient sanitization of the 'export_date' parameter. An attacker with low privileges can exploit this remotely by tricking a user into interacting with a specially crafted URL. Successful exploitation allows for the execution of arbitrary JavaScript in the context of the victim's browser session. As of the disclosure date, the vendor has not responded, and no official patch is available for this rolling release product.
Affected products
- Akpali9 Attendance-Management-System up to 70b91fe38f4195b701a45f0edcd4f42d5f64aeee
Timeline
- 2026-07-12: advisory: Vulnerability published by VulDB/NVD