Open Ticket Request System (OTRS) 6.0.x before 6.0.13 allows an admin to conduct an XSS attack via a modified URL.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-19142.json"
[ { "events": [ { "introduced": "6.0.0" }, { "fixed": "6.0.13" } ] } ]