CVE-2025-13273: Campcodes School Fees Payment Management System ajax.php sql injection
A security flaw has been discovered in Campcodes School Fees Payment Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=deletepayment. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13273?
CVE-2025-13273 has been rated as a high severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2025-13273?
To fix CVE-2025-13273, input validation should be implemented to sanitize and escape all user-supplied input for the affected AJAX function.
What systems are affected by CVE-2025-13273?
CVE-2025-13273 affects version 1.0 of the Campcodes School Fees Payment Management System.
What type of vulnerability is CVE-2025-13273?
CVE-2025-13273 is classified as a SQL injection vulnerability.
Can CVE-2025-13273 be exploited remotely?
Yes, CVE-2025-13273 can be exploited remotely if the attacker manipulates the ID argument in the AJAX request.