QID 730246
Date Published: 2021-12-02
QID 730246: BQE BillQuick Web Suite SQL Injection Vulnerability
BQE BillQuick Web Suite is a web-based time tracking, project management and billing software.
CVE-2021-42258: It allows SQL injection for unauthenticated remote code execution.
Affected Versions:
BQE BillQuick Web Suite before version 22.0.9.1
QID Detection Logic:(Unauthenticated)
Attacker can exploit via SQL injection for unauthenticated remote code execution as MSSQLSERVER$ via xp_cmdshell.
Solution
Vendor has released patch, for more information please refer to CVE-2021-42258
Vendor References
- BillQuick Web Suite Release Notes -
billquick.net/download/Support_Download/BQWS2021Upgrade/WebSuite2021LogFile_9_1.pdf
CVEs related to QID 730246
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-42258 |
|