CVE-2021-42258
Description
BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware installation. SQL injection can, for example, use the txtID (aka username) parameter. Successful exploitation can include the ability to execute arbitrary code as MSSQLSERVER$ via xp_cmdshell.
Summary dbcve.org
SQL injection vulnerability in the txtID (username) parameter of BQE BillQuick Web Suite 2018 through 2021 before version 22.0.9.1 allows unauthenticated attackers to execute arbitrary operating system commands via the MSSQLSERVER$ service account using xp_cmdshell. This vulnerability was actively exploited in the wild in October 2021 for ransomware deployment.
Mitigation
Upgrade to BillQuick Web Suite version 22.0.9.1 or later to remediate. If immediate patching is not possible, deploy WAF rules to filter SQL injection payloads and investigate the environment for indicators of compromise given active exploitation.