Zadarma · Zadarma Telephony Api · CVE-2026-31845
**Name of the Vulnerable Software and Affected Versions**
Rukovoditel CRM versions prior to 3.6.5
**Description**
A reflected cross-site scripting (XSS) issue exists in the Zadarma telephony API endpoint '/api/tel/zadarma.php'. The application reflects user-supplied input from the `zd echo` GET parameter into the HTTP response without proper sanitization, output encoding, or content-type restrictions, allowing the execution of arbitrary JavaScript in the browser of a victim.
**Recommendations**
Update to a version newer than 3.6.4.
As a temporary workaround, avoid using the `zd echo` parameter in the '/api/tel/zadarma.php' endpoint.