Impact
The vulnerability arises from improper neutralization of user input when generating a web page, enabling stored cross‑site scripting (XSS) in the Johnson Controls FM Systems Employee application. If exploited, an attacker could inject and execute malicious scripts on the browsers of authenticated or unauthenticated users who view the affected page, potentially leading to data theft, session hijacking, or further compromise of the system.
Affected Systems
The affected product is Johnson Controls FM Systems Employee, versions earlier than 2025.3.1. No specific sub‑products or additional affected releases are mentioned beyond this version boundary.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity. The EPSS score of < 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog, further indicating limited or no active exploitation. Attackers would need to insert malicious input that is stored and later displayed, so the attack vector is user‑controlled data that persists on the server.
OpenCVE Enrichment