Red Hat Bugzilla – Bug 1086463
CVE-2014-0176 CFME: reflected XSS in several places due to missing JavaScript escaping
Last modified: 2015-01-29 04:32:39 EST
Martin Povolny of Red Hat report: There is a a reflected XSS in application/panel_control and a failure to escape JavaScript elements in CFME.
Acknowledgements: This issue was discovered by Martin Povolny of Red Hat.
This issue has been addressed in following products: CloudForms Management Engine 5.x Via RHSA-2014:0816 https://rhn.redhat.com/errata/RHSA-2014-0816.html