OX App Suite before frontend 7.10.6-rev24 allows XSS via a non-app deeplink such as the jslob API's registry sub-tree.
open-xchange ox app suite 7.10.6
open-xchange ox app suite