CVE-2021-42258
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply updates per vendor instructions.
BQE BillQuick Web Suite versions before 22.0.9.1 contain a SQL injection vulnerability in the login form that allows attackers to execute arbitrary code on the server without needing valid credentials. This critical flaw was actively exploited in October 2021 to deploy ransomware.
Unauthenticated SQL injection exists in the txtID (username) parameter of BQE BillQuick Web Suite 2018-2021 (before 22.0.9.1). Successful exploitation enables arbitrary SQL command execution and code execution via xp_cmdshell under the MSSQLSERVER$ service account, with no authentication required.
The full analysis of this CVE is available in Portuguese →