An authenticated user can disclose the cleartext password of a configured SMTP server via an HTTP GET request to the /config.php endpoint.
Weakness
The product stores a password in plaintext within resources such as memory or files.
Potential Mitigations
References