Payments are experiencing issues due to temporary restrictions in Russia. If your payment does not go through, please submit a support request.Our support team is available 24/7 — we are always here to help with hosting and server issues.We are now accepting requests for dedicated server rental and colocation services in our data center.Reminder: we recommend enabling backups for additional data protection.A new VPS/VDS lineup with NVMe storage and improved performance is now available.Maintenance work on some servers has been completed. All services are operating normally.

MODULE FOR 1C-BITRIX

KURATOV

Lead automation in Bitrix24 from website forms on 1C-Bitrix

The module provides integration between web forms on a 1C-Bitrix site and the Bitrix24 CRM system via webhook. It enables automatic data transfer from forms to CRM, allows detailed field mapping configuration, duplicate lead detection, and preservation of marketing information.

Technical details

Published
20 October 2025
Updated
14 September 2026
Version
1.0.3
Installed
Fewer than 50 times
Responsive design
No
Composite support
No
Compatible with Sites24
No
Developer
KURATOV

What this solution does

The module provides integration between web forms on a 1C-Bitrix site and the Bitrix24 CRM system via webhook. It enables automatic data transfer from forms to CRM, allows detailed field mapping configuration, duplicate lead detection, and preservation of marketing information.

The module automates the transfer of leads from 1C-Bitrix website forms to Bitrix24 CRM. Connection to the system is established via webhook authorization using the REST API to create records. An integrated connection error handling mechanism ensures operational stability.

Field mapping is configured through a visual interface, allowing flexible alignment of form fields with any standard or custom CRM fields, including support for multiple fields. Configuration is saved directly to the database.

The system prevents duplicate creation by searching for existing leads based on phone number and email. Upon detecting matches, flexible rules are applied to update existing records rather than creating new ones. The module fully supports the transmission of UTM tags, traffic source preservation, and cookie data for end-to-end analytics. Marketing data is automatically passed to corresponding CRM fields, and a deal is automatically created for each lead.

During data processing, normalization occurs: phone numbers are converted to international format for accurate duplicate detection, while the original input format (including input masks) is preserved. Email and phone number validation is performed. When creating a lead, a responsible manager can be automatically assigned by selecting from the Bitrix24 employee list.

Default responsible user configuration

Lead name assignment

In the field mapping section, you can select a web form field whose data will be used as the lead name when creating a record in Bitrix24 CRM.

The module provides integration between 1C-Bitrix web forms and Bitrix24. The tool simplifies data transfer configuration, offers an intuitive management interface, and reduces implementation time.

When needed, General iT can implement “Lead automation in Bitrix24 from website forms on 1C-Bitrix”, configure the module and verify it against the current website setup.

UPDATE HISTORY

What’s new

3 releases
1.0.3 (14.09.2026)Latest update

Security fixes.

Incomplete permission check (install/files/test_connection.php): the webhook verification endpoint required only authentication, not administrator rights — unlike the neighboring get_field_mappings.php/save_field_mappings.php. Any authenticated site user could initiate outgoing requests on behalf of the server and write text to the event log. Added a check for $USER->IsAdmin(), as with the neighboring endpoints.

SSRF, residual risk (lib/Ajax/TestConnection.php): the webhookUrl check was supplemented with validation of the path structure (rest/id/code), matching the actual Bitrix24 webhook format. The check was moved to the reusable method TestConnection::isValidWebhookUrl().

Validation desynchronization (options.php): when saving module settings, webhook_url was accepted without validation, whereas TestConnection enforces a strict allowlist for the same purpose. The unvalidated saved value was later used for outgoing requests when processing web forms. Now, the same check (TestConnection::isValidWebhookUrl()) is applied upon saving.

Information leak in the event log (lib/Integration/UtmHandler.php): logUtmData(), in the absence of UTM tags, wrote raw values of cookies utm_*/BITRIX_SM_*, GET parameters, a full dump of $_SESSION, and the session ID in plain text to the Bitrix event log; the event log is readable by all users with access to the section. Now, only the fact of presence and the length of values are logged, without the values themselves. Additionally: the value $_COOKIE['BITRIX_SM_SALE_SL'] is now validated for format before being passed to CSession::GetByID().

1.0.2 (08.09.2026)

Compatibility with PHP 8.2 and security fixes.

The kuratovru_webformintegrationb24 module class did not explicitly declare the $installDir property and wrote to it via $this->installDir, which in PHP 8.2 is marked as deprecated dynamic property creation (deprecated: creation of dynamic property). The property is explicitly declared in install/index.php.

Stored XSS (options.php): CRM field names and web form field names (set by users with CRM/form permissions, not necessarily the site administrator) were inserted into the DOM via innerHTML without escaping when opening the field mapping settings popup. A malicious user's script could execute in the site administrator's browser. Rewritten to safely build the DOM using createElement/textContent.

1.0.1 (17.08.2026)

Fixed the transfer of attached files from the web form to the Bitrix24 lead.

Improved lead source determination via UTM tags.

Security issues resolved: added CSRF token validation and URL validation for the webhook during connection testing, stopped writing debug information to an open site directory, and added output escaping in module settings.

USER EXPERIENCE

Solution reviews

How does this solution work in a real project? Share your experience and help others choose.

Be the first to share your experience

There are no reviews of this solution on git.ru yet. Tell us what worked well and what could be improved.

Verified purchaseAdd a key if you wish. A verified review gets a badge, priority placement and more rating weight.

Open to every clientJust sign in to your account. A key is optional; all reviews are moderated.

YOUR EXPERIENCE MATTERS

Your review

YOUR PROJECT INFRASTRUCTURE

A home for your website

BEFORE YOU ORDER

Let’s go through the details.

What does the price cover?
The displayed price covers the solution itself. Platform licensing, installation and customisation are checked separately. If the page offers bundles, select the required option before submitting a request.
How do I check compatibility?
Compare the supported editions and solution version in the technical details with your project. Before installing on a live website, we recommend making a backup and checking the solution in a test environment.
Is there a trial?
The developer lists a trial of 10 days. The trial button opens the installer in your website control panel. Check the required features and compatibility before purchasing.
How much does this solution’s renewal cost?
The current renewal price is 950 ₽. Before you order, a manager will confirm the renewal period and whether it applies to your licence.
Can you help with implementation?
We can help install the module, check its settings and verify how it works in your project. Compatibility with other customisations and the scope of work are assessed before we begin.

GENERAL iT

Let’s discuss your project

Получатель: ООО «Дженерал Ай Ти Рус»

1C-BITRIX

Install solution

Enter a domain with or without https://. The installer will open in your website control panel in a new tab.

Solution screenshots

Solution screenshot