Unrated severityNVD Advisory· Published Sep 26, 2012· Updated Apr 29, 2026
CVE-2012-5163
CVE-2012-5163
Description
Cross-site scripting (XSS) vulnerability in oc-admin/ajax/ajax.php in OSClass before 2.3.5 allows remote attackers to inject arbitrary web script or HTML via the id parameter in an enable_category action to index.php.
Affected products
1Patches
1ff7ef8a97301https://github.com/osclass/OSClassvia nvd-ref
Vulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
5- osclass.org/2012/01/16/osclass-2-3-5/nvdPatchVendor Advisory
- secunia.com/advisories/47697nvdVendor Advisory
- github.com/osclass/OSClass/commit/ff7ef8a97301aaaf6a97fe46c2c27981a86b4e2fnvdVendor Advisory
- www.codseq.it/advisories/multiple_vulnerabilities_in_osclassnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/78962nvd
News mentions
0No linked articles in our index yet.