SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2022-35497

MEDIUM · CVSS 5.4 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Trimble TM4WEB version 21.4.0.4 is vulnerable due to a security misconfiguration that allows attackers to exploit reflected cross-site scripting (XSS) to recover valid session cookies from the external document viewer endpoint. This vulnerability could lead to unauthorized access to user sessions, potentially compromising sensitive data. Organizations using this version of TM4WEB should prioritize remediation to protect against session hijacking risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2022-35497
Severity
MEDIUM
CVSS
5.4
EPSS
0.26%

Original NVD Description

In Trimble TM4WEB 21.4.0.4 due to security misconfiguration with session identifiers, it is possible to recover valid session cookies via reflected cross-site scripting affecting the external document viewer endpoint.