-
Notifications
You must be signed in to change notification settings - Fork 910
Please fix the exploit, thanks! CVE-2022-29360 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29360 https://www.ddosi.org/cve-2022-29360/ https://www.youtube.com/watch?v=6dSiQH0pijk #2180
Comments
https://blog.sonarsource.com/rainloop-emails-at-risk-due-to-code-flaw/
|
Hi @Corsh,
However, this patch requires PHP 7 I don't know if I could switch to SnappyMail, because I need the plugin ldap-change-password that I had modified to generate extra password for samba attributes : sambaNTPassword and sambaLMPassword. Fortunately you are here to help us on Rainloop ! |
I had the following error with the sonarsource patch for this on
Here is a patch for
|
RainLoop version, browser, OS:
RainLoop v1.16.0 latest version
Expected behavior and actual behavior:
Steps to reproduce the problem:
Logs or screenshots:
CVE-2022-29360
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29360
https://www.ddosi.org/cve-2022-29360/
https://www.youtube.com/watch?v=6dSiQH0pijk
The text was updated successfully, but these errors were encountered: