Red Hat Satellite before 6.5 is vulnerable to a XSS in discovery rule when you are entering filter and you use autocomplete functionality.
https://projects.theforeman.org/issues/22042
https://euvd.enisa.europa.eu/vulnerability/EUVD-2017-3750
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12175