PT-2026-32121 · Unknown+1 · Rukovoditel Crm+1
Shukrullo Raximov
·
Published
2026-04-11
·
Updated
2026-04-11
·
CVE-2026-31845
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Rukovoditel CRM versions 3.6.4 and earlier
Description
A reflected cross-site scripting (XSS) issue exists in the Zadarma telephony API endpoint ('/api/tel/zadarma.php'). The application reflects user-supplied input from the
zd echo GET parameter into the HTTP response without proper sanitization. The vulnerable code directly outputs the value of the zd echo parameter using the exit() function. An unauthenticated attacker can exploit this by crafting a malicious URL containing JavaScript payloads. When a victim visits the link, the payload executes in the victim's browser, potentially leading to session hijacking, credential theft, phishing, or account takeover.Recommendations
Update to version 3.7 or later, which includes proper input validation and output encoding to prevent script injection.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rukovoditel Crm
Zadarma Telephony Api