CRITICAL

CVE-2021-42258

Bqe Billquick Web Suite 2021-10-22 CVSS v3.1
CVSS
9.8
KEV

Description

BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware installation. SQL injection can, for example, use the txtID (aka username) parameter. Successful exploitation can include the ability to execute arbitrary code as MSSQLSERVER$ via xp_cmdshell.

Summary dbcve.org

SQL injection vulnerability in the txtID (username) parameter of BQE BillQuick Web Suite 2018 through 2021 before version 22.0.9.1 allows unauthenticated attackers to execute arbitrary operating system commands via the MSSQLSERVER$ service account using xp_cmdshell. This vulnerability was actively exploited in the wild in October 2021 for ransomware deployment.

Mitigation

Upgrade to BillQuick Web Suite version 22.0.9.1 or later to remediate. If immediate patching is not possible, deploy WAF rules to filter SQL injection payloads and investigate the environment for indicators of compromise given active exploitation.

Proof of Concept

Weakness (CWE)

CWE-89 SQL Injection

EPSS Score

74.43%
Probability of exploitation in next 30 days
99.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE