RULE(RULE ID:338647)

Rule General Information
Release Date: 2025-01-14
Rule Name: Union West Mobile Store Management System treamToFile API Arbitrary File Upload Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: The Union West Mobile Store Management System is a management tool designed for physical retail chain stores. The system covers basic functions such as sales, inventory management and report statistics, which can meet the basic needs of daily operation of stores. There is a file upload vulnerability in StreamToFile interface of Western Union Software mobile store management system, through which an attacker without identity can arbitrarily execute code on the server side, write a backdoor, obtain server permissions, and then control the entire web server.
Impact: Attackers can upload viruses, Trojans, WebShell, other malicious scripts or pictures containing scripts to the server, and attackers can use these files for subsequent attacks.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.