---
id: CVE-2026-31845
title: >-
  A reflected cross-site scripting (XSS) vulnerability exists in Rukovoditel CRM
  version 3.6.4 and earlier in the Zadarma telephony API endpoint
  (/api/tel/zadarma.php)
summary: >-
  A reflected cross-site scripting (XSS) vulnerability exists in Rukovoditel CRM
  version 3.6.4 and earlier in the Zadarma telephony API endpoint
  (/api/tel/zadarma.php). The application directly reflects user-supplied input
  from the 'zd_ech…
severity: critical
cvss: 9.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'
cwe:
  - CWE-79
published: '2026-04-11'
updated: '2026-08-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-31845'
references:
  - url: 'https://forum.rukovoditel.net/viewtopic.php?p=22499#p22499'
    label: 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
tags:
  - nvd
epss: 0.00478
epssPercentile: 0.38646
ingestedAt: '2026-08-10T12:39:46.507Z'
---

## Overview

A reflected cross-site scripting (XSS) vulnerability exists in Rukovoditel CRM version 3.6.4 and earlier in the Zadarma telephony API endpoint (/api/tel/zadarma.php). The application directly reflects user-supplied input from the 'zd_echo' GET parameter into the HTTP response without proper sanitization, output encoding, or content-type restrictions.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
