Impact
The flaw is a reflected cross‑site scripting condition in the external document viewer endpoint of Trimble TM4WEB version 21.4.0.4. Session identifiers are included in the URL and the value is reflected without proper encoding. An attacker can embed malicious JavaScript in a crafted link that, based on the description, is inferred to require the victim to be an authenticated user when opened, running in that user's browser context and capturing the session cookie. The retrieved cookie can then be used to hijack the victim’s session, allowing unauthorized access to the application and potentially sensitive data. This weakness is categorized as CWE‑79, described as Cross‑Site Scripting.
Affected Systems
Trimble TM4WEB enterprise software, specifically version 21.4.0.4. No other product or version information is provided.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score of less than 1% suggests a low likelihood of widespread exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack requires an authenticated user to click a specially crafted URL that contains the unescaped session ID. Because the flaw is a reflected XSS, exploitation is straightforward for an attacker with knowledge of the impacted endpoint and does not need additional system access. However, successful exploitation would result in compromise of the victim’s session and the data accessible through that session.
OpenCVE Enrichment