Impact
A reflected cross‑site scripting flaw exists in the external bill viewer endpoint of Trimble TM4WEB 21.4.0.4. The flaw allows an attacker to insert a payload into an arbitrary URL parameter that is reflected in the browser without proper encoding, enabling the execution of malicious scripts in the context of the victim’s session.
Affected Systems
The affected product is Trimble TM4WEB version 21.4.0.4, specifically the external bill viewer endpoint. Users who access this endpoint via links containing crafted query parameters may be impacted.
Risk and Exploitability
Because the vulnerability relies on user interaction with a crafted URL, the attack vector is typically social or phishing‑based. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, so there is no official guidance on prevalence. However, reflected XSS can lead to credential theft, defacement, or execution of arbitrary code in the user’s browser, making the risk potentially high for organizations that rely on the bill viewer for sensitive data. Without a formal CVSS score, remediation should be prioritized based on the sensitivity of the data exposed through this endpoint.
OpenCVE Enrichment