Hackers Are Exploiting a Vulnerability in Billing Software to Deploy Ransomware | Huntress
ID: d1d7ad9d-c9f9-5562-96e7-22eb771fd348
STIX ID: report--d1d7ad9d-c9f9-5562-96e7-22eb771fd348
Feed Name: Huntress Blog
Threat Score
Huntress discovered and publicly documented CVE-2021-42258, a critical SQL injection in BillQuick Web Suite that permits unauthenticated attackers to dump sensitive billing and user data and, when the database uses a privileged account (commonly sa), to enable xp_cmdshell and achieve remote code execution; the flaw was reproduced with sqlmap and observed being exploited to gain initial access and deploy ransomware in a victim environment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
