CVE-2025-13273
MEDIUMCampcodes School Fees Payment Management System - Injection
Title source: ruleDescription
A security flaw has been discovered in Campcodes School Fees Payment Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_payment. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
References (5)
Scores
CVSS v3
6.3
EPSS
0.0004
EPSS Percentile
10.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Classification
CWE
CWE-74
CWE-89
Status
published
Affected Products (1)
campcodes/school_fees_payment_management_system
Timeline
Published
Nov 17, 2025
Tracked Since
Feb 18, 2026