Reflected XSS Vulnerability in SNOMED International Snowstorm
CVE-2026-66300
2.3LOW
What is CVE-2026-66300?
SNOMED International Snowstorm is susceptible to a reflected Cross-Site Scripting (XSS) vulnerability that arises from its 'Web Route' redirection feature. An attacker can exploit this flaw by crafting malicious links designed to execute arbitrary JavaScript within the context of a victim's browser. This risk could lead to unauthorized actions or data exposure, underscoring the importance of timely patching. The vulnerability has been addressed in the releases 10.12.2 and 10.9.3.
Affected Version(s)
Snowstorm 7.0.0 < 10.12.2
Snowstorm 10.12.2
Snowstorm 10.9.3
References
CVSS V4
Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Michael Milkovich, CISA
Karl Meister, CISA
