8.1
CVSSv3

CVE-2020-7613

Published: 07/04/2020 Updated: 21/07/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

clamscan up to and including 1.2.0 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the `_is_clamav_binary` function located within `Index.js`. It should be noted that this vulnerability requires a pre-requisite that a folder should be created with the same command that will be chained to execute. This lowers the risk of this issue.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

clamscan project clamscan

Vendor Advisories

clamscan through 120 is vulnerable to Command Injection It is possible to inject arbitrary commands as part of the `_is_clamav_binary` function located within `Indexjs` It should be noted that this vulnerability requires a pre-requisite that a folder should be created with the same command that will be chained to execute This lowers the risk ...