EXPOSURES › CVE-2021-42258
CVE-2021-42258
CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 95/100
ransomwarerceexploited-in-wild
BQE's BillQuick Web Suite had a SQL injection vulnerability allowing unauthenticated remote code execution, and it's actively being exploited in ransomware attacks.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution.
SENTIMENT · TRUSTED SOURCES
synthesis
severe-fallout
-0.80
Widespread condemnation and negative publicity due to the severity of the vulnerability and its potential impact.
Neutral reporting of the vulnerability.
"BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution."
Neutral, descriptive listing.
"CVE, short for Common Vulnerabilities and Exposures, is a list of publicly disclosed computer security flaws."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.