PT-2026-32121 · Unknown+1 · Rukovoditel Crm+1

Shukrullo Raximov

·

Published

2026-04-11

·

Updated

2026-04-11

·

CVE-2026-31845

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Rukovoditel CRM versions 3.6.4 and earlier
Description A reflected cross-site scripting (XSS) issue exists in the Zadarma telephony API endpoint ('/api/tel/zadarma.php'). The application reflects user-supplied input from the zd echo GET parameter into the HTTP response without proper sanitization. The vulnerable code directly outputs the value of the zd echo parameter using the exit() function. An unauthenticated attacker can exploit this by crafting a malicious URL containing JavaScript payloads. When a victim visits the link, the payload executes in the victim's browser, potentially leading to session hijacking, credential theft, phishing, or account takeover.
Recommendations Update to version 3.7 or later, which includes proper input validation and output encoding to prevent script injection.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-31845

Affected Products

Rukovoditel Crm
Zadarma Telephony Api