From Cybersecurity and Infrastructure Security Agency ↗
Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content.
The following versions of Johnson Controls OpenBlue Employee are affected:
OpenBlue Employee (FMS Employee)