Zarafa WebApp 2.0.1.47791 and earlier contains an unauthenticated reflected cross-site scripting vulnerability. An attacker can execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site.
View the template here CVE-2019-7219.yaml
References:
https://stash.kopano.io/repos?visibility=public