Cross-site scripting (XSS) vulnerability in the web frontend in OpenCA 0.9.1-8 and earlier, and 0.9.2 RC6 and earlier, allows remote attackers to inject arbitrary web script or HTML via the form input fields.
https://exchange.xforce.ibmcloud.com/vulnerabilities/17274
http://www.securityfocus.com/bid/11113