Description
In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via injection in a arbitrary parameter appended to the URL.
Published: 2026-09-04
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Reflected Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

A reflected cross‑site scripting flaw exists in the external bill viewer endpoint of Trimble TM4WEB 21.4.0.4. The flaw allows an attacker to insert a payload into an arbitrary URL parameter that is reflected in the browser without proper encoding, enabling the execution of malicious scripts in the context of the victim’s session. The CVSS score is 7.1, indicating a high severity.

Affected Systems

The affected product is Trimble TM4WEB version 21.4.0.4, specifically the external bill viewer endpoint. Users who access this endpoint via links containing crafted query parameters may be impacted.

Risk and Exploitability

Because the vulnerability relies on user interaction with a crafted URL, the attack vector is typically social or phishing‑based. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, so there is no official guidance on prevalence. Reflected XSS can lead to credential theft, defacement, or execution of arbitrary code in the user’s browser, and the CVSS score of 7.1 indicates a high severity that should prompt prompt remediation for organizations that rely on the bill viewer for sensitive data.

Generated by OpenCVE AI on September 4, 2026 at 22:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Trimble TM4WEB to a version that eliminates the reflected XSS flaw in the bill viewer endpoint.
  • If a patch is not available, apply strict input validation or output encoding to all URL parameters used by the bill viewer to prevent reflected script execution.
  • Restrict the bill viewer endpoint to authenticated users only or isolate it behind network segmentation so that only trusted traffic can reach it.

Generated by OpenCVE AI on September 4, 2026 at 22:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Title Reflected Cross‑Site Scripting in Trimble TM4WEB 21.4.0.4 Bill Viewer Endpoint

Fri, 04 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Trimble
Trimble tm4web
Vendors & Products Trimble
Trimble tm4web
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Reflected Cross‑Site Scripting in Trimble TM4WEB 21.4.0.4 Bill Viewer Endpoint
Weaknesses CWE-79

Fri, 04 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via injection in a arbitrary parameter appended to the URL.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-04T17:07:06.773Z

Reserved: 2022-07-11T00:00:00.000Z

Link: CVE-2022-35499

cve-icon Vulnrichment

Updated: 2026-09-04T17:01:40.289Z

cve-icon NVD

Status : Deferred

Published: 2026-09-04T16:17:19.963

Modified: 2026-09-08T19:39:43.673

Link: CVE-2022-35499

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T23:00:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')