The Email Viewer in RainLoop through 1.6.0 allows XSS via a crafted email message.
{ "ubuntu_priority": "medium" }