CVE-2026-34497
Received Received - Intake

Cross-Site Scripting (XSS) in Johnson Controls FM Systems Employee

Vulnerability report for CVE-2026-34497, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-31

Last updated on: 2026-07-31

Assigner: Johnson Controls

Description

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS). This issue affects FM Systems Employee: before 2025.3.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-31
Last Modified
2026-07-31
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
johnson_controls fmsystems_employee to 2025.3.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-80 The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a basic Cross-Site Scripting (XSS) vulnerability caused by improper neutralization of Script-Related HTML tags in Johnson Controls FM Systems Employee software. It allows attackers to inject malicious scripts into web pages viewed by users.

Detection Guidance

Detecting this XSS vulnerability requires manual review of web application inputs handling HTML tags. Check user input fields in FM Systems Employee for improper neutralization of script-related tags. Use browser developer tools to inspect network requests and responses for unfiltered HTML/script content.

Impact Analysis

An attacker could exploit this to steal user session cookies, redirect users to malicious sites, or perform actions on behalf of users. Users of affected FM Systems Employee versions before 2025.3.1 are at risk.

Mitigation Strategies

Upgrade FM Systems Employee to version 2025.3.1 or later. Implement input validation to block script-related HTML tags. Use output encoding to neutralize any injected scripts. Apply web application firewall rules to filter malicious payloads.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-34497. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart