PT-2026-57538 · Akpali9 · Attendance Management System
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Akpali9 Attendance-Management-System versions up to 70b91fe38f4195b701a45f0edcd4f42d5f64aeee
Description
Remote cross site scripting occurs due to improper processing of the
absent.php file. An attacker can initiate the attack by manipulating the export date argument.Recommendations
Avoid using the
export date argument in the absent.php file until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Attendance Management System