This has been fixed. More information can be found in the first line in the MDaemon release notes:
[10385] fix to WorldClient HTML injection vulnerability
This has been fixed. More information can be found in the first line in the MDaemon release notes:
[10385] fix to WorldClient HTML injection vulnerability