Jan Hutař reports: There is stored XSS vulnerability in user details field in Satellite server, they can be exploited by using the REST API to send XML data containing malformed data.
*** This bug has been marked as a duplicate of bug 1181152 ***