November 3, 2021 · Applied Cybernetics Group
CVE-2021-42258 — BQE BillQuick Web Suite
known ransomware use
BQE BillQuick Web Suite SQL Injection Vulnerability
- Added to KEV
2021-11-03- Federal due date
2021-11-17- Vendor
- BQE
- Product
- BillQuick Web Suite
- EPSS
- 99.9th percentile (score 0.941, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2021-42258
CISA short description
BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution.
Required action
Apply updates per vendor instructions.