Description
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS).

This issue affects FM Systems Employee: before 2025.3.1.
Published: 2026-07-31
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of script‑related HTML tags in the Johnson Controls FM Systems Employee web interface allows the injection and execution of arbitrary JavaScript code in a victim's browser. The vulnerability is a reflected cross‑site scripting flaw that can be triggered by feeding malicious input into the application, resulting in client‑side code execution. The official advisory states this as a moderate‑impact flaw with a CVSS score of 4.8.

Affected Systems

Johnson Controls FM Systems Employee installations prior to release 2025.3.1 are affected. The vulnerability is localized to the employee module of the web interface.

Risk and Exploitability

The EPSS score of less than 1 % indicates that exploitation attempts are currently rare. The flaw is not listed in the CISA KEV catalog. The CVSS score of 4.8 reflects limited impact focused on client‑side execution and does not imply server compromise. An attacker would need to supply malicious input that is reflected without proper escaping, making the attack manual or opportunistic rather than automated.

Generated by OpenCVE AI on August 3, 2026 at 09:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade FM Systems Employee to version 2025.3.1 or later to apply the required input sanitization.
  • Ensure that any user‑supplied data is properly encoded before rendering in HTML to prevent script injection.
  • Implement a Content Security Policy that disallows inline scripts and restricts script sources to trusted origins to mitigate the effect of any unescaped input.

Generated by OpenCVE AI on August 3, 2026 at 09:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Johnsoncontrols
Johnsoncontrols fm Systems Employee
Vendors & Products Johnsoncontrols
Johnsoncontrols fm Systems Employee

Fri, 31 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS). This issue affects FM Systems Employee: before 2025.3.1.
Title FMS Employee Vulnerable to HTML Injection
First Time appeared Johnson Controls
Johnson Controls fm Systems Employee
Weaknesses CWE-80
CPEs cpe:2.3:a:johnson_controls:fm_systems_employee:*:*:*:*:*:*:*:*
Vendors & Products Johnson Controls
Johnson Controls fm Systems Employee
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Johnson Controls Fm Systems Employee
Johnsoncontrols Fm Systems Employee Fms Employee
cve-icon MITRE

Status: PUBLISHED

Assigner: jci

Published:

Updated: 2026-07-31T18:10:50.071Z

Reserved: 2026-03-30T08:25:11.763Z

Link: CVE-2026-34497

cve-icon Vulnrichment

Updated: 2026-07-31T18:10:47.087Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-31T18:17:14.457

Modified: 2026-08-10T19:45:30.383

Link: CVE-2026-34497

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T10:00:12Z

Weaknesses
  • CWE-80

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)