SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2022-35499

HIGH · CVSS 7.1 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Trimble TM4WEB version 21.4.0.4 is susceptible to reflected cross-site scripting (XSS) through an arbitrary parameter in the URL of the external bill viewer endpoint. This vulnerability could allow attackers to execute malicious scripts in the context of the user's session, potentially leading to data theft or session hijacking. Organizations using this version of TM4WEB should prioritize patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2022-35499
Severity
HIGH
CVSS
7.1
EPSS
0.29%

Original NVD Description

In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via injection in a arbitrary parameter appended to the URL.