First published: Thu Jul 28 2022(Updated: )
The Email Viewer in RainLoop through 1.6.0 allows XSS via a crafted email message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RainLoop Webmail | <=1.16.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29360 is a vulnerability in the Email Viewer of RainLoop webmail software through version 1.6.0, allowing cross-site scripting (XSS) attacks through a specially crafted email message.
The severity of CVE-2022-29360 is medium, with a CVSS score of 5.4.
CVE-2022-29360 affects RainLoop webmail versions up to and including 1.6.0 by allowing an attacker to execute cross-site scripting (XSS) attacks by sending a malicious email message.
To mitigate the vulnerability in RainLoop webmail (CVE-2022-29360), it is recommended to update to the latest version of RainLoop (1.6.1 or newer) which includes a fix for the XSS vulnerability.
Yes, you can find additional information about CVE-2022-29360 in the references provided: [link1], [link2], [link3].