CyberRota Analysis
AI-GeneratedThe Trimble TM4WEB version 21.4.0.4 is susceptible to reflected cross-site scripting (XSS) through an arbitrary parameter in the URL of the external bill viewer endpoint. This vulnerability could allow attackers to execute malicious scripts in the context of the user's session, potentially leading to data theft or session hijacking. Organizations using this version of TM4WEB should prioritize patching to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via injection in a arbitrary parameter appended to the URL.