OX App Suite prior to 7.10.6-rev30 allows XSS via an activity tracking adapter defined by jslob.
open-xchange ox app suite 7.10.6
open-xchange ox app suite