logo

Hackers Are Exploiting a Vulnerability in Billing Software to Deploy Ransomware | Huntress

ID: d1d7ad9d-c9f9-5562-96e7-22eb771fd348

STIX ID: report--d1d7ad9d-c9f9-5562-96e7-22eb771fd348

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2024-06-24

Date Updated: 2026-04-28

...
...

Huntress discovered and publicly documented CVE-2021-42258, a critical SQL injection in BillQuick Web Suite that permits unauthenticated attackers to dump sensitive billing and user data and, when the database uses a privileged account (commonly sa), to enable xp_cmdshell and achieve remote code execution; the flaw was reproduced with sqlmap and observed being exploited to gain initial access and deploy ransomware in a victim environment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.