Researchers have uncovered a code vulnerability in RainLoop, an open-source webmail client. The vulnerability is a Stored Cross Site-Scripting, or XSS, vulnerability tracked as CVE-2022-29360. An attacker can exploit the code vulnerability simply by sending a malicious email to a victim as a mail client. No official patch is available, and the vulnerability can be exploited in any RainLoop installation that runs with default configurations. RainLoop’s back end acts as a proxy between a user and their mail server.”]
Source: https://www.govinfosecurity.com/unpatched-rainloop-webmail-enables-theft-emails-a-18948