PT-2024-36492 · Gophish+1 · Gophish+1

Gabriel Ferreira De Menezes

·

Published

2024-12-19

·

Updated

2025-01-10

·

CVE-2024-55196

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GoPhish version 0.12.1
Description The issue allows an attacker to access cleartext passwords for the configured IMAP and SMTP servers due to insufficiently protected credentials in the Mail Server Configuration.
Recommendations For GoPhish version 0.12.1, consider disabling the Mail Server Configuration until a patch is available to prevent attackers from accessing cleartext passwords. Restrict access to the Mail Server Configuration to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2024-55196
GHSA-RV83-H68Q-C4WQ
GO-2025-3361
OPENSUSE-SU-2025:14624-1
OPENSUSE-SU-2025_0060-1
SUSE-SU-2025:0060-1

Affected Products

Gophish
Suse