CyberRota Analysis
AI-GeneratedA Cross-Site Scripting (XSS) vulnerability exists in the FM Systems Employee application from Johnson Controls, allowing attackers to inject malicious scripts into web pages. This flaw can lead to unauthorized access to user data and session hijacking, posing a significant risk to users of the affected application. Organizations using versions prior to 2025.3.1 should prioritize remediation to protect against potential exploitation.
Original NVD Description
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS). This issue affects FM Systems Employee: before 2025.3.1.
Related CVEs
Other vulnerabilities affecting the same vendor(s)