Insufficiently Protected Credentials in the Mail Server Configuration in GoPhish v0.12.1 allows an attacker to access cleartext passwords for the configured IMAP and SMTP servers.
https://github.com/hexkaster/SecurityResearch/blob/main/CVE-2024-55196.md