In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, region, and endpoint.
Weakness
The product makes resources available to untrusted parties when those resources are only intended to be accessed by the product.
References