Executive brief
Johnson Controls FM Systems Employee, a workplace management tool, is affected by a security vulnerability that could allow an attacker to inject malicious scripts into the application's web interface. If exploited, this could allow an attacker to perform actions on behalf of other users or access sensitive information within the platform. The risk is mitigated by the fact that an attacker would need high-level administrative privileges and a legitimate user would need to interact with a malicious link or page.
Technical details
A basic Cross-Site Scripting (XSS) vulnerability exists in Johnson Controls FM Systems Employee due to CWE-80 (Improper Neutralization of Script-Related HTML Tags in a Web Page). The flaw allows a remote attacker with high privileges (PR:H) to inject malicious scripts into web pages viewed by other users. Exploitation requires user interaction (UI:P) from the victim. Successful exploitation could lead to a limited loss of confidentiality (VC:L). The issue is resolved in version 2025.3.1.
Affected products
- Johnson Controls FM Systems Employee before 2025.3.1
Timeline
- 2026-07-31: disclosed: Initial advisory publication
- 2025.3.1: patched: Vulnerability fixed in this version