Vulnerability Description
In TechSmith SnagIt 11.2.1 through 20.0.3, an XML External Entity (XXE) injection issue exists that would allow a local attacker to exfiltrate data under the local Administrator account.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Techsmith | Snagit | >= 11.2.1, <= 20.0.3 |
Related Weaknesses (CWE)
References
- https://support.techsmith.com/hc/en-us/articles/115006435067-Snagit-Windows-VersVendor Advisory
- https://support.techsmith.com/hc/en-us/articles/115006435067-Snagit-Windows-VersVendor Advisory
FAQ
What is CVE-2020-11541?
CVE-2020-11541 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In TechSmith SnagIt 11.2.1 through 20.0.3, an XML External Entity (XXE) injection issue exists that would allow a local attacker to exfiltrate data under the local Administrator account.
How severe is CVE-2020-11541?
CVE-2020-11541 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-11541?
Check the references section above for vendor advisories and patch information. Affected products include: Techsmith Snagit.