Security Advisory
CVE-2025-48046
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
An authenticated user can disclose the cleartext password of a configured SMTP server via an HTTP GET request to the /config.php endpoint.