Hide Forgot
Missed escaping in live output can allow XSS, when the execution code produces a valid HTML/JavaScript code.
Created from redmine issue http://projects.theforeman.org/issues/17066
Upstream bug assigned to inecas
Fixing in 6.4 GA https://bugzilla.redhat.com/show_bug.cgi?id=1399326