Cross-site scripting (XSS) vulnerability in memcp.php in XMB U2U Instant Messenger allows remote authenticated users to inject arbitrary web script or HTML via the recipient field.
https://exchange.xforce.ibmcloud.com/vulnerabilities/31661
https://docs.xmbforum2.com/index.php?title=Security_Issue_History
http://www.securityfocus.com/archive/1/457630/100/0/threaded