Seriously, does nobody else see this as an issue? You ask users to set their own password and boom you now have their password on the export extension csv
The reason these passwords are in the clear is because the .csv is used to move some / all extensions from one PBX to another. Some people add new extensions in via the .csv file and if the system expected an encrypted password for the extension, it wouldn't be able to be added in this batch format.
I don't see the issue here currently, if you're able to export the extensions, you're also able to change the passwords via the Management Console.