{"id":"CVE-2019-13389","details":"RainLoop Webmail before 1.13.0 lacks XSS protection mechanisms such as xlink:href validation, the X-XSS-Protection header, and the Content-Security-Policy header.","modified":"2026-07-08T19:51:05.297389Z","published":"2020-03-20T19:15:12.580Z","references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/05/msg00027.html"},{"type":"FIX","url":"https://github.com/RainLoop/rainloop-webmail/commit/8eb4588917b4741889fdd905d4c32e3e86317693"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/rainloop/rainloop-webmail","events":[{"introduced":"0"},{"fixed":"cdfe5fb232e085b7ef86f2adce66ca03536dc7af"},{"fixed":"8eb4588917b4741889fdd905d4c32e3e86317693"}],"database_specific":{"cpe":"cpe:2.3:a:rainloop:webmail:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.13.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v1.12.1","v1.12.0","v1.11.3","v1.11.2","v1.10.5.192","v1.11.1","v1.11.0.203","v1.11.0.201-beta.1","v1.10.4.183","v1.10.4.181","v1.10.4.180","v1.10.4.179","v1.10.4.177-beta.3","v1.10.4.176-beta.2","v1.10.4.160-beta.1","v1.10.3.151","v1.10.3.150-beta.1","v1.10.2.145","v1.10.2.141","v1.10.2.140","v1.10.2.137-beta.4","v1.10.2.136-beta.3","v1.10.2.133-beta.2","v1.10.2.131-beta.1","v1.10.1.127","v1.10.1.123","v1.10.1.121-beta.2","v1.10.1.117-beta.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-13389.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}