Hackers use SQL injection bug in BillQuick billing app to deploy ransomware
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-42258 | Unauthenticated SQL Injection RCE in BQE BillQuick Web Suite CVE-2021-42258 is an unauthenticated SQL injection flaw (CWE-89) in BQE BillQuick Web Suite 2018 through 2021, fixed in version 22.0.9.1, that can be triggered through user-supplied input such as the txtID (username) parameter of the web interface. Because attacker-controlled input reaches the backend Microsoft SQL Server, an unauthenticated attacker with network access to the web suite can inject SQL and abuse xp_cmdshell to execute arbitrary code on the database server under the MSSQLSERVER$ account. This yields full unauthenticated remote code execution, and in observed intrusions it was used to deploy ransomware. Any organization running an affected BillQuick Web Suite release is affected, particularly those exposing the billing portal directly to the internet. The flaw is actively exploited in the wild (added to CISA KEV on 2021-11-03 with known ransomware use) and carries a high EPSS score of 74.4%, making urgent patching advisable. Do: Upgrade BillQuick Web Suite to version 22.0.9.1 or later per BQE's instructions, as required by the CISA KEV entry. Until patched, restrict internet-facing access to the Web Suite server and review logs for SQL injection attempts against the username (txtID) parameter, unexpected xp_cmdshell usage, or commands running as MSSQLSERVER$; the referenced Huntress advisory includes indicators of compromise for the October 2021 ransomware campaign. | 9.8 | 74% | KEV ransomware PoC |
| nichelikely low thousands of installations worldwide, with only hundreds of internet-exposed instances |
Full article353 words · extracted from therecord.media · click to collapse
At least one hacking group is exploiting a security flaw in a popular billing software suite to gain initial access, take over servers, and then deploy ransomware inside companies’ networks. Discovered by Huntress Labs this month, the attacks targeted BillQuick Web Suite, a billing solution developed by California-based BQE. “Hackers were able to successfully exploit CVE-2021-42258—using it to gain initial access to a US engineering company—and deploy ransomware across the victim’s network,” Caleb Stewart, a security researcher for Huntress Labs, said over the weekend. Stewart said Huntress investigated the attack and was able to reproduce the attacker’s exploit, described as an SQL injection vulnerability in the app’s login page. “Simply navigating to the login page and entering a single quote (`’`) can trigger this bug,” Steward said. “Further, the error handlers for this page display a full traceback, which could contain sensitive information about the server-side code.” Huntress said the vulnerability could be abused to dump the content of the MSSQL database used by the BillQuick software and even for remote code execution scenarios that would allow hackers control over the entire server. This is how Huntress believes the threat actor was able to enter customer networks and deploy ransomware. In addition to the SQL injection bug exploited in the ransomware attacks, Stewart said Huntress also discovered eight other vulnerabilities in the BillQuick software during their investigation. All issues were reported to the vendor, which released patches for the actively exploited CVE-2021-42258 in WebSuite 2021 version 22.0.9.1 on October 7, while fixes for the other eight issues are forthcoming. Huntress is now warning customers who still run BillQuick Web Suite 2018 to 2021 v22.0.9.0 to update their billing suites. According to the BQE website, the company claims more than 400,000 customers. A BQE spokesperson was not immediately available for comment.Eight other issues also discovered; patches available
No previous article
No new articles
Catalin Cimpanu
is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/hackers-use-sql-injection-bug-in-billquick-billing-app-to-deploy-ransomware