SquirrelMail can be caused to insert the scripting malicious JavaScript and HTML code, while it displays incoming emails. This is due to the fact that read_body.php does not filter incoming users input of the `mailbox' and `passed_id' variables.
Credit:
The information has been provided by euronymous.
Vendor response:
(To the author) Thank you for pointing this out. We would have been a lot more grateful if you had notified us of this issue prior to releasing the post, and it would have been fixed in our 1.2.10 release, which as you pointed out was released just yesterday. The lack of forward notification is frustrating, and it would have been nice to have heard earlier.
Next time any issues such as this arise, please feel free to contact the project administrators/leaders (such as myself), which can all be found listed on http://www.squirrelmail.org/about.php.