CVE-2021-42258
Summary
| CVE | CVE-2021-42258 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-10-22 22:15:00 UTC |
| Updated | 2021-10-28 20:34:00 UTC |
| Description | BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware installation. SQL injection can, for example, use the txtID (aka username) parameter. Successful exploitation can include the ability to execute arbitrary code as MSSQLSERVER$ via xp_cmdshell. |
Risk And Classification
EPSS: 0.732690000 probability, percentile 0.994030000 (date 2026-07-22)
CISA KEV: Listed on 2021-11-03; due 2021-11-17; ransomware use Known
Problem Types: CWE-89
CISA Known Exploited Vulnerability
| Vendor | BQE |
|---|---|
| Product | BillQuick Web Suite |
| Name | BQE BillQuick Web Suite SQL Injection Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2021-42258 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bqe | Billquick Web Suite | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Threat Advisory: Hackers Are Exploiting a Vulnerability in Popular Billing Software to Deploy Ransomware | MISC | www.huntress.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 730246 BQE BillQuick Web Suite SQL Injection Vulnerability