possible XSS exploit on OT with [move] feature?

looks like color does not get closed when it is around move marquee. tryin to figure out what i can do with this

it seems so. but if its just formatting, i doubt its harmful to the point of an emergency update/patch.