CVE-2021-42258 is a critical SQL injection vulnerability affecting BQE BillQuick Web Suite versions 2018 through 2021 before 22.0.9.1. This flaw allows unauthenticated remote attackers to execute arbitrary code, for example, by manipulating the txtID (username) parameter to leverage xp_cmdshell as MSSQLSERVER$. The vulnerability carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. It has been actively exploited in the wild, notably in October 2021 for ransomware deployment, and has publicly available exploit modules in Metasploit and Nuclei, garnering significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 19, < 22.0.9.1CPE matchmatch criteria | cpe:2.3:a:bqe:billquick_web_suite:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.