OX App Suite through 7.10.5 allows XSS via a trailing control character such as the SCRIPT\t substring.