Impact
The vulnerability lies in the handling of the export_date argument in absent.php, typifying a CWE‑79 Cross‑Site Scripting flaw and potentially a CWE‑94 Code Injection vulnerability. Attackers can inject and execute arbitrary JavaScript in the victim's browser, enabling the theft of session cookies, defacement, or impersonation of the user’s actions.
Affected Systems
The Akpali9 Attendance‑Management‑System is affected. No specific version numbers are listed; the product rolls releases continuously, so all current and prior deployments may remain vulnerable until a patch is issued by the vendor.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate risk. The EPSS score is <1%, and the issue is not listed in CISA KEV, but the remote nature of the attack means that exploitation is possible over the network without local access. In the absence of a vendor fix, the risk remains until further mitigations are applied.
OpenCVE Enrichment