CVE-2025-13270: Campcodes School Fees Payment Management System ajax.php sql injection
A vulnerability was found in Campcodes School Fees Payment Management System 1.0. This affects an unknown function of the file /ajax.php?action=savecourse. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13270?
CVE-2025-13270 has been assessed as having a high severity due to the potential for remote SQL injection attacks.
How do I fix CVE-2025-13270?
To fix CVE-2025-13270, you need to sanitize and validate all user inputs in the /ajax.php?action=save_course function to prevent SQL injection.
What systems are affected by CVE-2025-13270?
CVE-2025-13270 affects Campcodes School Fees Payment Management System version 1.0.
Can CVE-2025-13270 be exploited remotely?
Yes, CVE-2025-13270 can be exploited remotely, allowing attackers to manipulate the ID parameter.
What are the potential impacts of CVE-2025-13270?
The potential impacts of CVE-2025-13270 include unauthorized access to the database and data leakage.