PostfixAdmin could be made to run malicious JavaScript in the user's browser if it received specially crafted input.

Source: Ubuntu 24.04 PostfixAdmin An Important Fix for XSS Attack USN-8242-2