Description
In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via injection in a arbitrary parameter appended to the URL.
Published: 2026-09-04
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A reflected cross‑site scripting flaw exists in the external bill viewer endpoint of Trimble TM4WEB 21.4.0.4. The flaw allows an attacker to insert a payload into an arbitrary URL parameter that is reflected in the browser without proper encoding, enabling the execution of malicious scripts in the context of the victim’s session.

Affected Systems

The affected product is Trimble TM4WEB version 21.4.0.4, specifically the external bill viewer endpoint. Users who access this endpoint via links containing crafted query parameters may be impacted.

Risk and Exploitability

Because the vulnerability relies on user interaction with a crafted URL, the attack vector is typically social or phishing‑based. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, so there is no official guidance on prevalence. However, reflected XSS can lead to credential theft, defacement, or execution of arbitrary code in the user’s browser, making the risk potentially high for organizations that rely on the bill viewer for sensitive data. Without a formal CVSS score, remediation should be prioritized based on the sensitivity of the data exposed through this endpoint.

Generated by OpenCVE AI on September 4, 2026 at 16:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Trimble TM4WEB to a version that eliminates the reflected XSS flaw in the bill viewer endpoint.
  • If a patch is not available, apply strict input validation or output encoding to all URL parameters used by the bill viewer to prevent reflected script execution.
  • Restrict the bill viewer endpoint to authenticated users only or isolate it behind network segmentation so that only trusted traffic can reach it.

Generated by OpenCVE AI on September 4, 2026 at 16:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Trimble
Trimble tm4web
Vendors & Products Trimble
Trimble tm4web
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Reflected Cross‑Site Scripting in Trimble TM4WEB 21.4.0.4 Bill Viewer Endpoint
Weaknesses CWE-79

Fri, 04 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via injection in a arbitrary parameter appended to the URL.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-04T17:07:06.773Z

Reserved: 2022-07-11T00:00:00.000Z

Link: CVE-2022-35499

cve-icon Vulnrichment

Updated: 2026-09-04T17:01:40.289Z

cve-icon NVD

Status : Received

Published: 2026-09-04T16:17:19.963

Modified: 2026-09-04T18:17:44.527

Link: CVE-2022-35499

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T17:15:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')