FlawAtlas
Search the atlas
CVE-2024-55196 High

GoPhish sends cleartext passwords in github.com/gophish/gophish

GoPhish sends cleartext passwords in github.com/gophish/gophish

Exploit probability 0.4%
Published January 7, 2025
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Go github.com/gophish/gophish
Go github.com/gophish/gophish

04 / EVIDENCE

Source records

Open Source Vulnerabilities GO-2025-3361

GoPhish sends cleartext passwords in github.com/gophish/gophish

View original source
Open Source Vulnerabilities GHSA-rv83-h68q-c4wq

Insufficiently Protected Credentials in the Mail Server Configuration in GoPhish v0.12.1 allows an attacker to access cleartext passwords for the configured IMAP and SMTP servers.

View original source

05 / REFERENCES

Further evidence