prive/formulaires/configurerpreferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, displaynavigation, displayoutils, imessage, and spipecran parameters.
{ "urgency": "not yet assigned" }