Unknown · Baseweb Jsite · CVE-2025-3970
**Name of the Vulnerable Software and Affected Versions**
baseweb JSite versions up to 1.0
**Description**
A problematic issue has been found in baseweb JSite. The manipulation of the `Remarks` argument leads to cross-site scripting. It is possible to launch the attack remotely.
**Recommendations**
For versions up to 1.0, consider restricting access to the `/sys/office/save` file until a fix is available.
As a temporary workaround, avoid using the `Remarks` argument in the affected function until the issue is resolved.