CVE-2025-13269: Campcodes School Fees Payment Management System ajax.php sql injection
A vulnerability has been found in Campcodes School Fees Payment Management System 1.0. The impacted element is an unknown function of the file /ajax.php?action=savepayment. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13269?
CVE-2025-13269 is classified as a high severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2025-13269?
To fix CVE-2025-13269, sanitize and parameterize inputs to prevent SQL injection in the /ajax.php?action=save_payment function.
Who is affected by CVE-2025-13269?
The vulnerability CVE-2025-13269 affects users of Campcodes School Fees Payment Management System version 1.0.
What type of vulnerability is CVE-2025-13269?
CVE-2025-13269 is an SQL injection vulnerability that allows remote attackers to manipulate database queries.
Can CVE-2025-13269 be exploited remotely?
Yes, CVE-2025-13269 can be exploited remotely by attackers to execute unauthorized SQL commands.