CVE-2025-26485

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
19/03/2025
Last modified:
02/07/2025

Description

A vulnerability in Beta80 Life 1st enables the retrieval of different error messages for failed authentication attempts <br /> (in case of the usage of a wrong password or a non existent user). The difference in the <br /> returned error messages could be used by attackers to understand whether a <br /> certain user is registered in the Identity Manager.<br /> <br /> <br /> This issue affects Life 1st: 1.5.2.14234.