[Bug 1129756] New: VUL-1: CVE-2019-9752: otrs: attacker who is logged into OTRS as an agent or a customer user may upload a carefully crafted resource in order to cause execution of JavaScript in the context of OTRS