New XSS vector in ReaderMode with %READER-TITLE-NONCE%