the generic attribute writer used for these two spots does not escape what it
writes, so a value taken from the message ends the attribute and starts a new
one. both are inside a part that is compiled, which is where an injected
handler runs.
* the organizer link took inEvent.organizer.email verbatim. a value such as
mailto:x@y" onpointerover="... produced a live handler on the anchor, and an
entity encoded scheme such as javascript: reached the href, where the
browser decodes it. the href is now built as mailto: plus the parsed address
and escaped as an attribute value.
* the attachment name paragraph of the image and the link viewer took
filenameForDisplay verbatim. a quote inside an RFC 2231 encoded filename
ended the title attribute. the writer escapes & < > there but not the quote,
so the accessor drops the quote instead of escaping it, which keeps a plain
filename such as A&B.pdf unchanged in the tooltip.
the img title of the image viewer is left alone: attributes of that element are
escaped by the framework already.