An issue was discovered in SmartFoxServer 2.17.0. Cleartext password disclosure can occur via /config/server.xml.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Smartfoxserver | Smartfoxserver | 2.17.0 (including) | 2.17.0 (including) |