Impact
The vulnerability is a reflected cross‑site scripting flaw in the Web Route redirection feature of SNOMED International Snowstorm. An attacker can embed malicious JavaScript in a URL that, when a victim follows the link, executes in the victim’s browser. This allows the attacker to steal browser cookies, hijack sessions, or deface the page, but it does not give direct access to the server or data beyond what the user’s session permits. The weakness is classified as CWE‑79.
Affected Systems
Affected deployments of Snowstorm include any installations running versions prior to the fix. The vendor released an update that addresses the issue in release 10.12.2 for the main branch and 10.9.3 for the long‑term support branch. Users running older versions are vulnerable if they provide the redirection route to external users.
Risk and Exploitability
The CVSS score is 2.3, indicating a low overall risk, and the vulnerability is not listed in CISA’s KEV catalog. Because the flaw is reflected and relies on a crafted link, it requires the victim to click the malicious URL, which is a typical phishing vector. No authentication or privileged access is needed, but the impact is confined to the victim’s browser session. The lack of an EPSS score suggests no data on exploitation frequency, but the straightforward exploitation path makes the risk primarily user‑oriented.
OpenCVE Enrichment