OTRS is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Credit:
The information has been provided by Mike Eduard.
Vulnerable Systems:
* OTRS 2.4.x versions prior to 2.4.15
* OTRS 3.0.x versions prior to 3.0.17
* OTRS 3.1.x versions prior to 3.1.11
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials, or to control how the site is rendered to the user. Other attacks are also possible.