description:The application suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file /xml/User/User.xml
and obtain administrative login information that allows for a successful authentication bypass attack.