CVE-2026-59109
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-20
Validación incorrecta de entrada
Fecha de publicación:
13/08/2026
Última modificación:
13/08/2026
Descripción
*** Pendiente de traducción *** SQL injection in the Zalktis accounting application via<br />
trading-partner-controlled text fields in received electronic invoices. When<br />
importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis<br />
concatenates partner-controlled values directly into SQL statement text using<br />
string concatenation, with neither parameterised queries nor escaping. The<br />
application&#39;s own escaping helper, Dazadi.sql_txt(),<br />
is not invoked on these code paths, so a party that sends an invoice can break<br />
out of the string literal and alter the query logic.<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
This issue affects Zalktis: before 2026.1.586 and before 2026.2.592.
Impacto
Puntuación base 4.0
8.70
Gravedad 4.0
ALTA
Puntuación base 3.x
8.80
Gravedad 3.x
ALTA



