OX App Suite through 7.10.4 allows XSS via JavaScript in a Note referenced by a mail:// URL.

By admin