Turn on the forceclean config setting when a user is logged in as a different user. This is a precautionary measure, which forces all user submitted content to be cleaned of JavaScript before rendering it to the logged in as user.