In section "HOST"->"Create Host", In tab "Additional Information", field "Comment" is vulnerable to stored cross-site scripting. As a result of the attack, an attacker with an existing account on the system can steal another user's session, make requests on behalf of the user, and get user credentials.
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2023-0119
This issue has been addressed in the following products: Red Hat Satellite 6.13 for RHEL 8 Via RHSA-2023:3387 https://access.redhat.com/errata/RHSA-2023:3387
This issue has been addressed in the following products: Red Hat Satellite 6.14 for RHEL 8 Via RHSA-2023:6818 https://access.redhat.com/errata/RHSA-2023:6818