CVE-2025-12612: Campcodes School Fees Payment Management System ajax.php sql injection
A security flaw has been discovered in Campcodes School Fees Payment Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=deletecourse. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12612?
CVE-2025-12612 has been classified as a high severity vulnerability due to the potential for remote SQL injection attacks.
How do I fix CVE-2025-12612?
To fix CVE-2025-12612, you should update your Campcodes School Fees Payment Management System to the latest version that addresses this vulnerability.
What systems are affected by CVE-2025-12612?
CVE-2025-12612 specifically affects Campcodes School Fees Payment Management System version 1.0.
Can CVE-2025-12612 be exploited remotely?
Yes, CVE-2025-12612 can be exploited remotely, allowing attackers to perform SQL injection attacks through the affected system.
What are the risks associated with CVE-2025-12612?
The risks associated with CVE-2025-12612 include unauthorized access to sensitive data, data manipulation, and potential control over the database server.