CVE-2020-25158: Bbraun Datamodule Compactplus
Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.
A reflected cross-site scripting (XSS) vulnerability in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows remote attackers to inject arbitrary web script or HTML into various locations.
Affected products
- Bbraun Datamodule Compactplus: version a10 only; version a11 only
- Bbraun Spacecom: up to and including l81
Published 2022-04-14. Last modified 2026-06-17.