Skip to content
COOEY

EXPOSURES › CVE-2021-42258

CVE-2021-42258

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-42258 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 95/100 ransomwarerceexploited-in-wild

BQE's BillQuick Web Suite had a SQL injection vulnerability allowing unauthenticated remote code execution, and it's actively being exploited in ransomware attacks.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.80
Widespread condemnation and negative publicity due to the severity of the vulnerability and its potential impact.
cooey ↗ severe-fallout -0.70
Neutral reporting of the vulnerability.
"BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution."
www.cvefind.com ↗ severe-fallout +0.00
Neutral, descriptive listing.
"CVE, short for Common Vulnerabilities and Exposures, is a list of publicly disclosed computer security flaws."
nypost.com ↗ severe-fallout +1.00
Irrelevant to the event.
"(empty string)"
techcrunch.com ↗ severe-fallout +1.00
Irrelevant to the event.
"(empty string)"
www.seattletimes.com ↗ severe-fallout +1.00
Irrelevant to the event.
"(empty string)"
gizmodo.com ↗ severe-fallout +1.00
Irrelevant to the event.
"(empty string)"
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.