CVE-2025-12873 | Campcodes School File Management 1.0 /admin/update_user.php user_id sql injection
A vulnerability has been found in Campcodes School File Management 1.0 and classified as critical. This affects an unknown part of the file /admin/update_user.php. Performing manipulation of the argument user_id results in sql injection.
This vulnerability is cataloged as CVE-2025-12873. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.