CVE-2025-13274: Campcodes School Fees Payment Management System ajax.php sql injection
A weakness has been identified in Campcodes School Fees Payment Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=deletefees. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13274?
CVE-2025-13274 has not been assigned a specific severity score, but it involves a SQL injection vulnerability which can lead to significant data breaches.
How do I fix CVE-2025-13274?
To fix CVE-2025-13274, ensure proper input validation and parameterized queries are implemented in the affected functionality of the file /ajax.php.
What is affected by CVE-2025-13274?
CVE-2025-13274 affects the Campcodes School Fees Payment Management System version 1.0, specifically through the /ajax.php?action=delete_fees functionality.
What type of vulnerability is CVE-2025-13274?
CVE-2025-13274 is a SQL injection vulnerability that can be exploited through argument manipulation.
Can CVE-2025-13274 be exploited remotely?
Yes, CVE-2025-13274 can potentially be exploited remotely by manipulating the ID argument.