ZeroHour

CVE-2022-35499

niche

Reflected XSS in Trimble TM4WEB External Bill Viewer

CVSS 3.1
7.1 high
EPSS
<1%p21
Published
()
Modified
AI analysis

Trimble TM4WEB 21.4.0.4 contains a reflected cross-site scripting flaw (CWE-79) in its external bill viewer endpoint, where script injected into an arbitrary parameter appended to the URL is returned to the user's browser without proper sanitization. An attacker triggers it by crafting a malicious link containing the injected payload and persuading an authenticated or browsing user to click it, since user interaction is required (CVSS UI:R). Successful exploitation lets the attacker run arbitrary JavaScript in the context of the bill-viewer site, enabling theft of session cookies or tokens, manipulation of the displayed bill content, or phishing within the trusted portal (CVSS scope-changed with low confidentiality and integrity impact). Affected parties are organizations running TM4WEB 21.4.0.4 — typically utilities and their billing portals — and the customers who use those externally exposed bill-viewer pages. Exploitation is not currently observed: the flaw is not in CISA KEV, has no known public proof-of-concept, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.

What to do: Contact Trimble support for a patched TM4WEB release beyond 21.4.0.4 and apply it, since no fixed version number is published in the available data. Until patched, sanitize/validate and HTML-encode all URL parameters on the bill viewer endpoint, consider a WAF or CSP rule to block script injection via arbitrary query parameters, and warn helpdesk staff to treat unsolicited bill-viewer links as potentially attacker-crafted.

Affected
Trimble TM4WEB (external bill viewer endpoint)21.4.0.4 (version cited in the advisory; no fixed version or full affected range provided in the data)
Estimated exposure
nichelikely at most a few hundred internet-facing utility bill-viewer portals; precise count unknown — TM4WEB is a specialized utility-billing web portal whose bill-viewer endpoints are externally exposed by design, but it serves a narrow municipal/utility customer base and no public install counts or scan data exist, so only a small…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via injection in a arbitrary parameter appended to the URL.

Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.