CVE-2022-35497

NONE
CVSS v3
CVSS v2
0.26% EPSS (exploit probability)
CWE

Description

In Trimble TM4WEB 21.4.0.4 due to security misconfiguration with session identifiers, it is possible to recover valid session cookies via reflected cross-site scripting affecting the external document viewer endpoint.

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references