CVE-2025-26485

A vulnerability in Beta80 Life 1st enables the retrieval of different error messages for failed authentication attempts (in case of the usage of a wrong password or a non existent user). The difference in the returned error messages could be used by attackers to understand whether a certain user is registered in the Identity Manager. This issue affects Life 1st: 1.5.2.14234.
Configurations

No configuration.

History

No history.

Information

Published : 2025-03-19 16:15

Updated : 2025-07-02 15:15


NVD link : CVE-2025-26485

Mitre link : CVE-2025-26485

CVE.ORG link : CVE-2025-26485


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor