CVE Database
/

CVE-2020-7613

Back to search

CVE-2020-7613

Published: Apr 7, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

clamscan through 1.2.0 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the `_is_clamav_binary` function located within `Index.js`. It should be noted that this vulnerability requires a pre-requisite that a folder should be created with the same command that will be chained to execute. This lowers the risk of this issue.

VendorProductVersions

n/a

clamscan

affected
All versions including 1.2.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now