Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Shukrullo Raximov

#28610of 56,330
9.3Total CVSS
Vulnerabilities · 1
PT-2026-32121
9.3
2026-04-11
Zadarma · Zadarma Telephony Api · CVE-2026-31845
**Name of the Vulnerable Software and Affected Versions** Rukovoditel CRM versions prior to 3.6.5 **Description** A reflected cross-site scripting (XSS) issue exists in the Zadarma telephony API endpoint '/api/tel/zadarma.php'. The application reflects user-supplied input from the `zd echo` GET parameter into the HTTP response without proper sanitization, output encoding, or content-type restrictions, allowing the execution of arbitrary JavaScript in the browser of a victim. **Recommendations** Update to a version newer than 3.6.4. As a temporary workaround, avoid using the `zd echo` parameter in the '/api/tel/zadarma.php' endpoint.