An authenticated user can disclose the cleartext password...
Moderate severity
Unreviewed
Published
May 29, 2025
to the GitHub Advisory Database
•
Updated Sep 5, 2025
Description
Published by the National Vulnerability Database
May 29, 2025
Published to the GitHub Advisory Database
May 29, 2025
Last updated
Sep 5, 2025
An authenticated user can disclose the cleartext password of a configured SMTP server via an HTTP GET request to the /config.php endpoint.
References