Specially crafted string in OTRS system configuration can allow the execution of any system command.
https://github.com/post-cyberlabs/CVE-Advisory
https://otrs.com/release-notes/otrs-security-advisory-2022-03/
https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html