1. The mod_security is your server is giving a false positive because of too strict rule
or
2. your browser in infected
-- You may try
1. disabling mod_security in your server by add this in your .htaccess file of joomla root folder:
SecFilterScanPOST Off
2. or ask your administrator to examine logs, and find which mod_security Rule is giving this false positive, and remove/change the Rule.