Executive brief
Trimble TM4WEB is a document management and viewing application used by organizations to store and access important business documents. Due to improper session handling combined with a reflected cross-site scripting vulnerability in the external document viewer, attackers can steal valid session cookies and hijack user accounts to access confidential documents and project data.
Technical details
The vulnerability is a reflected cross-site scripting (XSS) flaw in the external document viewer endpoint of TM4WEB 21.4.0.4, combined with insecure session identifier configuration. An attacker crafts a malicious URL containing JavaScript payload that, when clicked by a victim, executes in their browser context and extracts the session cookie. The stolen session identifier can then be reused to impersonate the victim. The vulnerability requires user interaction (clicking a malicious link) but can be delivered via email or social engineering. No authentication is required from the attacker's perspective to craft or send the exploit. Patches or workarounds should be verified with Trimble support.
Affected products
- Trimble TM4WEB 21.4.0.4
Timeline
- 2022-09-04: disclosed