This issue has been confirmed. Thank you for reporting!
As the affecting data can only be added by a privileged user, and the adding of the data is protected from CSRF by a form token, we won't be pushing out a new release specifically to deal with this issue. It will be handled as a regular bug report and folded into the next patch release alongside other bug fixes.
As the affecting data can only be added by a privileged user, and the adding of the data is protected from CSRF by a form token, we won't be pushing out a new release specifically to deal with this issue. It will be handled as a regular bug report and folded into the next patch release alongside other bug fixes.