OX App Suite up to and including 7.10.4 allows XSS via an appointment in which the location contains JavaScript code.
open-xchange open-xchange appsuite