ZSA-2019-04
Execution of arbitrary Javascript code via URL manipulation
Problem
An attacker who is logged into OTRS as an agent can execute JavaScript by manipulating the URL.
Workaround
As a workaround, you can replace the affected files.
Solution
Upgrade to the latest available OTRS patch level (https://ftp.otrs.org/pub/otrs/).