Description-Behavior Mismatch
Medium
- Confidence
- 96% confidence
- Finding
- The template explicitly includes an initial password in plaintext email content, which is insecure because email is commonly stored, forwarded, logged, and accessible from multiple devices or mailbox compromises. Sending credentials this way increases the chance of account takeover if the message is intercepted or the recipient mailbox is later accessed by an unauthorized party.
