An attacker could send a specially prepared HTML email to OTRS. If he can then trick an agent into following a special link to display this email, JavaScript code would be executed (CVE-2014-1695).
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2014-0114.json"