Impact
Improper neutralization of script‑related HTML tags in the Johnson Controls FM Systems Employee web interface allows the injection and execution of arbitrary JavaScript code in a victim's browser. The vulnerability is a reflected cross‑site scripting flaw that can be triggered by feeding malicious input into the application, resulting in client‑side code execution. The official advisory states this as a moderate‑impact flaw with a CVSS score of 4.8.
Affected Systems
Johnson Controls FM Systems Employee installations prior to release 2025.3.1 are affected. The vulnerability is localized to the employee module of the web interface.
Risk and Exploitability
The EPSS score of less than 1 % indicates that exploitation attempts are currently rare. The flaw is not listed in the CISA KEV catalog. The CVSS score of 4.8 reflects limited impact focused on client‑side execution and does not imply server compromise. An attacker would need to supply malicious input that is reflected without proper escaping, making the attack manual or opportunistic rather than automated.
OpenCVE Enrichment