All you needed to do was send an email which contained a From header with script embedded in the name part:
From: "<script>Do evil</script>" <address@example.com>
All you needed to do was send an email which contained a From header with script embedded in the name part:
All I did to find this vulnerability was sign up for an account and then plonk the email address they gave me into https://emailprivacytester.com/ (of which I am the author)