CVE-2025-48046

Publication date

2025-05-29 12:33:27

Family

rapid7

State

PUBLISHED

Description

An authenticated user can disclose the cleartext password of a configured SMTP server via an HTTP GET request to the /config.php endpoint.