Not sure if $taboo was getting sanitized or not. Possibly an SQL injection vulnerability that allows maliciously crafted group names to inject SQL at a later date when the group CP is loaded. Unconfirmed, theoretical fix.
/* This class restores all CSS properties to that absolute positioning of fullscreen mode is correct */
.mceFullscreenPos {
display: block !important;
position: static !important;
left: 0 !important;
top: 0 !important;
bottom: auto !important;
right: auto !important;
width: auto !important;
height: auto !important;
margin: 0 !important;
padding: 0 !important;
border: 0 !important;
overflow: visible;
z-index: 1 !important;
clear: both;
}
body.mceFullscreen {
overflow: hidden !important;
}