I honestly didn't expect that to be the case, but I had to be sure. In my line of work, it's often pragmatic to assume the worst.
Might be easier to try it yourself in that case. Log out, then log in using any email address (I used yours seen as yours comes back as the default when a blank GET request is made, which is another issue I'd perhaps raise with your devs) and with just a * as the password. I think someone made a booboo when setting up your password definitions.
I'd be worried if your InfoSec, Testing and Dev teams have all missed this. This should be probably the first thing they check when checking functionality as part of their unit tests, formal functional testing, and security testing, and should have been done well before the system went live with a publicly accessible domain.