Vendor
Gophish versions through 0.12.1 contain a vulnerability in the API authentication middleware that fails to enforce account lockout and password change requirements, allowing attackers with valid API keys to maintain persistent unauthorized access.