Debian Security Advisory 1241-1 – In Squirrelmail, Martijn Brinkers discovered cross site scripting vulnerabilities in the the mailto parameter of webmail.php, the session and delete_draft parameters of compose.php and through a shortcoming in the magicHTML filter. An attacker could abuse these to execute malicious JavaScript in the user’s webmail session.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/53292/dsa-1241-1.txt
Source: https://packetstormsecurity.com/files/53292/Debian-Linux-Security-Advisory-1241-1.html