Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The post announces a reflected XSS vulnerability (CVE-2026-31845) in Rukovoditel CRM 3.6.4’s Zadarma Telephony API endpoint, linking to a detailed vulnerability report.
Infoflowcloud@infoflowcloudDisclosure
The tweet announces a reflected XSS vulnerability (CVE-2026-31845) in Rukovoditel CRM and Zadarma API, providing technical details but no proof‑of‑concept, exploit code, patch information, or evidence of active exploitation.
CVE@CVEnewDisclosure
The text discloses a reflected XSS flaw in Rukovoditel CRM 3.6.4 and earlier and the Zadarma API endpoint, without providing any proof‑of‑concept, exploit, or patch details.
CVEFind.com@CveFindComDisclosure
A reflected XSS flaw (CVE-2026-31845) was disclosed for Rukovoditel CRM 3.6.4, allowing arbitrary JavaScript via crafted URLs, with no evidence of exploits or patches mentioned.
0day Signal@0dayPublishingGeneral
The post announces CVE-2026-31845, describing an XSS vulnerability due to raw GET parameter reflection in a CRM telephony endpoint, without mentioning a PoC, exploit, patch, or ongoing exploitation.