Impact
The vulnerability allows an attacker to upload arbitrary files of dangerous type through the FM Systems Employee interface. This unrestricted file upload can be exploited to place malicious content on the server, potentially leading to further compromise or denial of service if the uploaded files are executed or processed by the application.
Affected Systems
Johnson Controls FM Systems Employee before version 2025.3.1. The affected product is the FM Systems Employee application from Johnson Controls.
Risk and Exploitability
The CVSS score is 4.8, indicating moderate severity. The EPSS score is less than 1%, suggesting low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is via the application’s file upload functionality accessible to authenticated users; exploitation would require an attacker to submit a malicious file to the upload endpoint, but no evidence of code execution or privilege escalation is documented.
OpenCVE Enrichment