Insufficiently Protected Credentials in the Mail Server Configuration in GoPhish v0.12.1 allows an attacker to access cleartext passwords for the configured IMAP and SMTP servers.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.