Releasit Releasit COD Form & Upsells OTP Validation client-side enforcement of server-side security
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 6.9epss 0.4%
exploitation probability
0.4%top 70% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A vulnerability was detected in Releasit Releasit COD Form & Upsells v1. This vulnerability affects unknown code of the component OTP Validation. The manipulation results in client-side enforcement of server-side security. The attack may be launched remotely. The exploit is now public and may be used. Upgrading to version v2 is able to resolve this issue. The affected component should be upgraded.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
Affected products
Releasit · Releasit COD Form & Upsellspublic PoCs found — 1
cve_referencegithub.com/chetansaini53/releasit-cod-otp-bypass-advisoryunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.