CVE-2026-66300: SNOMED International Snowstorm reflected XSS
SNOMED International Snowstorm contains a reflected XSS vulnerability within the "Web Route" redirection functionality. An attacker can inject arbitrary JavaScript which will execute upon a target user navigating to a crafted, malicious link. Fixed in 10.12.2 and 10.9.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SNOMED International Snowstormto a version that resolves this vulnerability.Fixed in 10.12.2 - Upgrade
Upgrade
SNOMED International Snowstormto a version that resolves this vulnerability.Fixed in 10.9.3