Threats Tagged 'cwe-544'
View all threats tagged with 'cwe-544'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-544'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2025-11750 is a medium severity vulnerability in langgenius/dify-web version 1.6.0 where the authentication mechanism leaks user account existence information through distinct error messages. This allows attackers to enumerate valid usernames or emails by analyzing login or registration error responses. Although it does not directly compromise passwords or system integrity, it facilitates targeted attacks such as social engineering, brute force, or credential stuffing. The vulnerability arises from missing standardized error handling (CWE-544), causing inconsistent error messages for non-existent versus existing accounts with incorrect passwords. No known exploits are currently reported in the wild. The CVSS score is 4.3, reflecting limited impact on confidentiality and integrity without affecting availability. European organizations using langgenius/dify-web should prioritize uniform error messaging and implement additional protections against account enumeration to reduce attack surface. Join the discussion | CVE Database V5 | 10/22/2025, 13:13:32 UTC Added: 10/22/2025, 13:31:15 UTC |
Showing 1 to 1 of 1 result