Impact
A reflected cross‑site scripting flaw exists in the external bill viewer endpoint of Trimble TM4WEB 21.4.0.4. The flaw allows an attacker to insert a payload into an arbitrary URL parameter that is reflected in the browser without proper encoding, enabling the execution of malicious scripts in the context of the victim’s session. The CVSS score is 7.1, indicating a high severity.
Affected Systems
The affected product is Trimble TM4WEB version 21.4.0.4, specifically the external bill viewer endpoint. Users who access this endpoint via links containing crafted query parameters may be impacted.
Risk and Exploitability
Because the vulnerability relies on user interaction with a crafted URL, the attack vector is typically social or phishing‑based. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, so there is no official guidance on prevalence. Reflected XSS can lead to credential theft, defacement, or execution of arbitrary code in the user’s browser, and the CVSS score of 7.1 indicates a high severity that should prompt prompt remediation for organizations that rely on the bill viewer for sensitive data.
OpenCVE Enrichment