[Bug Report] I found an XSS attack in the new profile settings but ...