Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the manageuser.php?action=edit address1 parameter.
{ "binaries": [ { "binary_version": "2.0+dfsg-6ubuntu1.1", "binary_name": "collabtive" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3298.json"