PT-2026-71703 · Zalktis · Zalktis
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zalktis versions prior to 2026.1.586
Zalktis versions prior to 2026.2.592
Description
An issue exists where the application concatenates partner-controlled values directly into SQL statement text during the import of received electronic invoices (UBL/PEPPOL) or e-commerce exports. This occurs because the system fails to use parameterized queries or the internal escaping helper function
Dazadi.sql txt(), allowing a sender to manipulate the query logic by breaking out of the string literal.Recommendations
Update to version 2026.1.586 or later.
Update to version 2026.2.592 or later.
Exploit
Fix
SQL injection
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zalktis