A vulnerability classified as problematic has been found in baseweb JSite up to 1.0. Affected is an unknown function of the file /sys/office/save. The manipulation of the argument Remarks leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
History

Mon, 12 May 2025 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Jsite
Jsite jsite
CPEs cpe:2.3:a:jsite:jsite:*:*:*:*:*:*:*:*
Vendors & Products Jsite
Jsite jsite

Mon, 28 Apr 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 27 Apr 2025 12:45:00 +0000

Type Values Removed Values Added
Description A vulnerability classified as problematic has been found in baseweb JSite up to 1.0. Affected is an unknown function of the file /sys/office/save. The manipulation of the argument Remarks leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Title baseweb JSite save cross site scripting
Weaknesses CWE-79
CWE-94
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-04-27T12:31:04.411Z

Updated: 2025-04-28T22:01:06.867Z

Reserved: 2025-04-26T07:14:39.050Z

Link: CVE-2025-3970

cve-icon Vulnrichment

Updated: 2025-04-28T14:46:25.869Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-27T13:15:14.550

Modified: 2025-05-12T19:08:11.613

Link: CVE-2025-3970

cve-icon Redhat

No data.