An issue was discovered in SuperWebMailer 9.00.0.01710. It allows keepalive.php XSS via a GET parameter.
- https://herolab.usd.de/security-advisories/usd-2023-0013/
No PoCs found on GitHub currently.