Impact
The vulnerability allows an attacker who can control trading‑partner fields in electronic invoices or e‑commerce exports to inject arbitrary SQL through string concatenation, bypassing the application’s normal escaping. This flaw can modify or leak accounting data by altering the query logic, thus compromising confidentiality and integrity of the database. The weakness is classified as CWE-89 and CWE-20.
Affected Systems
Zalktis Programmas, Zalktis accounting application. Versions before 2026.1.586 on the legacy branch and before 2026.2.592 on the current branch are affected.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, though EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the import of malicious e‑invoices or exports from untrusted partners; an attacker would need the ability to supply such imports, which typically requires network access to the import endpoint. While exploitation evidence is not documented, the high score and lack of mitigation make the risk substantial.
OpenCVE Enrichment