OCSInventory allow stored email template with special characters that lead to a Stored cross-site Scripting.
- https://fluidattacks.com/advisories/creed/
No PoCs found on GitHub currently.