Key Systems Inc Global Facilities Management Software Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in Key Systems Inc Global Facilities Management Software version 20230721a. The issue arises in the selectgroup and gn parameters on the /?Function=Groups endpoint, allowing remote attackers to execute arbitrary code. User-supplied input is improperly sanitized and encoded, enabling the injection of malicious JavaScript that executes in the context of other users' sessions.

Impact

Exploitation of this vulnerability allows for the injection of malicious JavaScript, which can execute in the context of other users' sessions. This could lead to unauthorized access to user session data, including session cookies, and allow attackers to perform actions on behalf of the user or steal sensitive information.

Reproduction

To reproduce this vulnerability, authenticate into the Global Facilities Management System web application and navigate to the Groups section. Edit the Group Name field by inserting a basic XSS payload, such as a script tag containing JavaScript code, and save the changes. The injected script will execute on any page where the Group Name is displayed, demonstrating the cross-site scripting vulnerability.

Added: Feb 20, 2026, 5:42 PM
Updated: Feb 20, 2026, 7:14 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
1.7
exploitability
6.0
remediation
0.0
relevance
3.2
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.