Martin Povolny of Red Hat report: There is a a reflected XSS in application/panel_control and a failure to escape JavaScript elements in CFME.
Acknowledgements: This issue was discovered by Martin Povolny of Red Hat.
This issue has been addressed in following products: CloudForms Management Engine 5.x Via RHSA-2014:0816 https://rhn.redhat.com/errata/RHSA-2014-0816.html