BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware installation. SQL injection can, for example, use the txtID (aka username) parameter. Successful exploitation can include the ability to execute arbitrary code as MSSQLSERVER$ via xp_cmdshell.
Conclusion & alert: CVE-2021-42258 is rated Critical Active Threat (94/100): CVSS Critical severity, with high exploitation likelihood (EPSS 73.27%, 99th percentile).Core evidence: CISA KEV confirms active exploitation (added 2021-11-03) affecting BQE / BillQuick Web Suite. SQL injection (CWE-89) Unauthenticated remote administrative access may be possible.Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
CISA KEV Record for CVE-2021-42258
Name: BQE BillQuick Web Suite SQL Injection Vulnerability · CISA KEV detail
Exploit added: 2021-11-03
Action due: 2021-11-17
Required action: Apply updates per vendor instructions.
Public exploit references (Exploit-DB) for CVE-2021-42258
Exploit prediction scoring system (EPSS) score for CVE-2021-42258
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).