Cross-site Scripting (XSS) - Stored in GitHub repository projectsend/projectsend prior to r1606.
https://huntr.dev/bounties/9294743d-7818-4264-b973-59de027d549b
https://github.com/projectsend/projectsend/commit/698be4ade1db6ae0eaf27c843a03ffc9683cca0a