A cross-site scripting flaw was found in Report Menu feature of Red Hat CloudForms 4.7 and 5. An attacker could use this flaw to execute a stored XSS attack on an application administrator using CloudForms.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-3190