Not sure if $taboo was getting sanitized or not. Possibly an SQL injection vulnerability that allows maliciously crafted group names to inject SQL at a later date when the group CP is loaded. Unconfirmed, theoretical fix.
+ − /* This class restores all CSS properties to that absolute positioning of fullscreen mode is correct */
+ − .mceFullscreenPos {
+ − display: block !important;
+ − position: static !important;
+ − left: 0 !important;
+ − top: 0 !important;
+ − bottom: auto !important;
+ − right: auto !important;
+ − width: auto !important;
+ − height: auto !important;
+ − margin: 0 !important;
+ − padding: 0 !important;
+ − border: 0 !important;
+ − overflow: visible;
+ − z-index: 1 !important;
+ − clear: both;
+ − }
+ −
+ − body.mceFullscreen {
+ − overflow: hidden !important;
+ − }