← Terug naar overzicht

CVE-2022-35499 affects Trimble TM4WEB version 21.4.0.4, a web-based transportation management application. The vulnerability exists in the external bill viewer endpoint, which is susceptible to reflected cross-site scripting (XSS). An attacker can inject malicious scripts via arbitrary parameters appended to the URL. Reflected XSS attacks can be used to steal session cookies, redirect users, or perform actions on behalf of victims. A proof-of-concept exploit has been published on GitHub by researcher PN-Tester. The vulnerability requires user interaction, typically via a crafted link sent to a victim. No authentication appears to be required to exploit the endpoint. Organizations using Trimble TM4WEB 21.4.0.4 should apply patches or mitigations as soon as available.

Affected products

  • Trimble TM4WEB 21.4.0.4

Related CVE's

  • CVE-2022-35499

Categories

  • Enterprise Applications
  • Web Technologies