CVE-2024-55196
High
GoPhish sends cleartext passwords in github.com/gophish/gophish
GoPhish sends cleartext passwords in github.com/gophish/gophish
Exploit probability
0.4%
Published
January 7, 2025
Required by
Not available
Last source change
March 3, 2026
02 / AFFECTED SOFTWARE
Affected packages
04 / EVIDENCE
Source records
Open Source Vulnerabilities
GO-2025-3361
View original source
GoPhish sends cleartext passwords in github.com/gophish/gophish
Open Source Vulnerabilities
GHSA-rv83-h68q-c4wq
View original source
Insufficiently Protected Credentials in the Mail Server Configuration in GoPhish v0.12.1 allows an attacker to access cleartext passwords for the configured IMAP and SMTP servers.
05 / REFERENCES