CVE-2022-35499
nicheReflected XSS in Trimble TM4WEB External Bill Viewer
Trimble TM4WEB 21.4.0.4 contains a reflected cross-site scripting flaw (CWE-79) in its external bill viewer endpoint, where script injected into an arbitrary parameter appended to the URL is returned to the user's browser without proper sanitization. An attacker triggers it by crafting a malicious link containing the injected payload and persuading an authenticated or browsing user to click it, since user interaction is required (CVSS UI:R). Successful exploitation lets the attacker run arbitrary JavaScript in the context of the bill-viewer site, enabling theft of session cookies or tokens, manipulation of the displayed bill content, or phishing within the trusted portal (CVSS scope-changed with low confidentiality and integrity impact). Affected parties are organizations running TM4WEB 21.4.0.4 — typically utilities and their billing portals — and the customers who use those externally exposed bill-viewer pages. Exploitation is not currently observed: the flaw is not in CISA KEV, has no known public proof-of-concept, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.
What to do: Contact Trimble support for a patched TM4WEB release beyond 21.4.0.4 and apply it, since no fixed version number is published in the available data. Until patched, sanitize/validate and HTML-encode all URL parameters on the bill viewer endpoint, consider a WAF or CSP rule to block script injection via arbitrary query parameters, and warn helpdesk staff to treat unsolicited bill-viewer links as potentially attacker-crafted.
| Trimble TM4WEB (external bill viewer endpoint) | 21.4.0.4 (version cited in the advisory; no fixed version or full affected range provided in the data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via injection in a arbitrary parameter appended to the URL.
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.