Junglewise Threat Intelligence

CVE-2021-42258: BQE BillQuick Web Suite SQL Injection Vulnerability

CVE-2021-42258 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Executive brief

BQE BillQuick Web Suite contains a SQL injection vulnerability in the txtID (username) parameter. An unauthenticated remote attacker can exploit this to execute arbitrary code as the MSSQLSERVER$ service account via xp_cmdshell, which has been observed in the wild for ransomware deployment.

Affected products

  • BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1

Timeline

  • 2021-10-22: disclosed: NVD Published Date
  • 2021-10-01: exploited: Exploited in the wild in October 2021 for ransomware installation.
  • 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog.