ZSA-2019-05
Execution of arbitrary Javascript code via OTRS appointment calendar
Problem
An attacker who is logged into OTRS as an agent can execute JavaScript by manipulating an appointment of the OTRS calendar.
Workaround
As a workaround, you can replace the affected files.
Solution
Upgrade to the latest available OTRS patch level (https://ftp.otrs.org/pub/otrs/).