Impact
The vulnerability arises from a misconfiguration in the session identifier handling of Trimble TM4WEB 21.4.0.4. Because session identifiers are reflected in the URLs of the external document viewer endpoint, an attacker can inject malicious input and trigger a reflected cross‑site scripting response that contains a valid session cookie. The attacker can recover and use this cookie to impersonate a legitimate user.
Affected Systems
Affected systems are the Trimble TM4WEB web application, specifically the 21.4.0.4 release. The product is identified by Trimble, and no other vendors or versions are reported.
Risk and Exploitability
The risk is that an attacker can hijack user sessions, gain unauthorized access to data or functionality, and potentially further compromise the system if the session privileges are high. The exploit only requires a remote attacker to send a crafted request to the exposed endpoint; no authentication is required. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the nature of the flaw makes it likely to be targetable.
OpenCVE Enrichment