In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via injection in a arbitrary parameter appended to the URL.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 04 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Reflected Cross‑Site Scripting in Trimble TM4WEB 21.4.0.4 Bill Viewer Endpoint | |
| Weaknesses | CWE-79 |
Fri, 04 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via injection in a arbitrary parameter appended to the URL. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-04T15:30:29.774Z
Reserved: 2022-07-11T00:00:00.000Z
Link: CVE-2022-35499
No data.
Status : Received
Published: 2026-09-04T16:17:19.963
Modified: 2026-09-04T16:17:19.963
Link: CVE-2022-35499
No data.
OpenCVE Enrichment
Updated: 2026-09-04T16:30:06Z
Weaknesses