In libraries/auth/cookie.auth.lib.php, the value of $GLOBALS['convcharset'] is not sanitized.
Patch for 2.11.2.1
Logged In: YES user_id=210714 Originator: YES
File Added: bug1835123.patch
Patch for 2.11.2.1
Logged In: YES
user_id=210714
Originator: YES
File Added: bug1835123.patch