{"id":"CVE-2022-35499","title":"In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via injection in a arbitrary parameter appended to the URL.","summary":"In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via injection in a arbitrary parameter appended to the URL.","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L","cwe":["CWE-79"],"published":"2026-09-04","updated":"2026-09-08","sourceUpdated":"2026-09-08T19:39:43.673","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-35499","references":[{"url":"http://tm4web.com","label":"cve@mitre.org"},{"url":"http://trimble.com","label":"cve@mitre.org"},{"url":"https://github.com/PN-Tester/CVE-2022-35499","label":"cve@mitre.org"},{"url":"https://github.com/PN-Tester/CVE-2022-35499","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","exploit-available"],"epss":0.00287,"epssPercentile":0.21477,"exploits":{"github":1,"githubRepos":["https://github.com/PN-Tester/CVE-2022-35499"],"checkedAt":"2026-09-21T15:27:39.915Z"},"exploitAvailable":true,"ingestedAt":"2026-09-08T20:10:03.166Z","slug":"CVE-2022-35499","body":"## Overview\n\nIn Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via injection in a arbitrary parameter appended to the URL.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":51,"depthScoreParts":{"impact":39.1,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}