CVE-2025-26485
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
19/03/2025
Last modified:
02/07/2025
Description
A vulnerability in Beta80 Life 1st enables the retrieval of different error messages for failed authentication attempts <br />
(in case of the usage of a wrong password or a non existent user). The difference in the <br />
returned error messages could be used by attackers to understand whether a <br />
certain user is registered in the Identity Manager.<br />
<br />
<br />
This issue affects Life 1st: 1.5.2.14234.
Impact
Base Score 3.x
5.80
Severity 3.x
MEDIUM



