CVE-2025-12873: Campcodes School File Management update_user.php sql injection
A security flaw has been discovered in Campcodes School File Management 1.0. This affects an unknown part of the file /admin/updateuser.php. Performing manipulation of the argument userid results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12873?
CVE-2025-12873 is considered a critical vulnerability due to the potential for remote SQL injection attacks.
How do I fix CVE-2025-12873?
To fix CVE-2025-12873, validate and sanitize user input for the user_id parameter in the /admin/update_user.php file.
What software is affected by CVE-2025-12873?
CVE-2025-12873 affects Campcodes School File Management version 1.0.
Can CVE-2025-12873 be exploited remotely?
Yes, CVE-2025-12873 can be exploited remotely through manipulation of the user_id parameter.
What type of vulnerability is CVE-2025-12873?
CVE-2025-12873 is classified as an SQL injection vulnerability.