CyberRota Analysis
AI-GeneratedTrimble TM4WEB version 21.4.0.4 is vulnerable due to a security misconfiguration that allows attackers to exploit reflected cross-site scripting (XSS) to recover valid session cookies from the external document viewer endpoint. This vulnerability could lead to unauthorized access to user sessions, potentially compromising sensitive data. Organizations using this version of TM4WEB should prioritize remediation to protect against session hijacking risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
In Trimble TM4WEB 21.4.0.4 due to security misconfiguration with session identifiers, it is possible to recover valid session cookies via reflected cross-site scripting affecting the external document viewer endpoint.