A vulnerability, which was classified as critical, was found in Campcodes School Fees Payment Management System 1.0. This issue affects some unknown processing of the file /ajax.php. The manipulation results in sql injection.

This vulnerability is identified as CVE-2025-12612. The attack can be executed remotely. Additionally, an exploit exists.