Mickaël Gallier reports:
There are several stored XSS vulnerabilities in various fields in Satellite
server, they can be exploited by using the REST API to send XML data
containing malformed data.
Created attachment 951111[details]
SW-master/Sat5-latest patch
This patch applies to the latest Spacewalk and Satellite5 codebase. Sat5.6 patch is still in progress.