OX App Suite through 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail message.