Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The example includes a raw password directly in the configuration file, which can lead users to store mail credentials in plaintext under their home directory. If the file is exposed through backups, local compromise, screenshots, dotfile sync, or accidental sharing, attackers can obtain email account access.
