Executive brief
BQE BillQuick Web Suite contains a SQL injection vulnerability in the txtID (username) parameter. An unauthenticated remote attacker can exploit this to execute arbitrary code as the MSSQLSERVER$ service account via xp_cmdshell, which has been observed in the wild for ransomware deployment.
Affected products
- BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1
Timeline
- 2021-10-22: disclosed: NVD Published Date
- 2021-10-01: exploited: Exploited in the wild in October 2021 for ransomware installation.
- 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog.