It was found [1] that Red Hat Satellite 6 WebUI has a bug which allows an authenticated user to perform an XSS attack. [1]: https://bugzilla.redhat.com/show_bug.cgi?id=1106417
This issue is now public: http://projects.theforeman.org/issues/6580
Statement: This issue was fixed in current releases of foreman on Satellite 6.