CVE-2026-84110 PUBLISHED

Releasit Releasit COD Form & Upsells OTP Validation client-side enforcement of server-side security

Assigner: VulDB
Reserved: 01.09.2026 Published: 01.09.2026 Updated: 01.09.2026

A vulnerability was detected in Releasit Releasit COD Form & Upsells v1. This vulnerability affects unknown code of the component OTP Validation. The manipulation results in client-side enforcement of server-side security. The attack may be launched remotely. The exploit is now public and may be used. Upgrading to version v2 is able to resolve this issue. The affected component should be upgraded.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
CVSS Score: 6.9

Product Status

Vendor Releasit
Product Releasit COD Form & Upsells
Versions
  • Version v1 is affected
  • Version v2 is unaffected

Credits

  • cyberac1d (VulDB User) reporter

References

Problem Types

  • Client-Side Enforcement of Server-Side Security CWE