An Excel Macro Injection vulnerability exists in the export feature in the B. Braun OnlineSuite Version AP 3.0 and earlier via multiple input fields that are mishandled in an Excel export.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HBbraun Onlinesuite Application Package
APPBbraun≤ 3.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2020-25172CRITICAL9.8PL ✓same product
Path Traversal w B. Braun OnlineSuite — nieautoryzowany upload/download plików
CVE-2020-25174HIGH7.8same product
A DLL hijacking vulnerability in the B. Braun OnlineSuite Version AP 3.0 and earlier allows local attackers to...
CVE-2021-33885CRITICAL10.0PL ✓same vendor
B. Braun SpaceCom2 — pominięcie weryfikacji podpisu danych, pełny dostęp do systemu
CVE-2020-25150HIGH7.6same vendor
A relative path traversal attack in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Da...
CVE-2020-25156HIGH7.2same vendor
Active debug code in the B. Braun Melsungen AG SpaceCom Version L8/U61, and the Data module compactplus Versio...