CVE-2025-13273

Source
https://cve.org/CVERecord?id=CVE-2025-13273
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-13273.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-13273
Published
2025-11-17T10:15:57.770Z
Modified
2026-03-15T14:54:03.085904Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A security flaw has been discovered in Campcodes School Fees Payment Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_payment. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-13273.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "1.0"
            }
        ]
    }
]