Description
Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.
Remediation
References
Related Vulnerabilities
WordPress Plugin MailPoet Newsletters (Previous) Cross-Site Scripting (2.6.11)
Nginx Improper Encoding or Escaping of Output Vulnerability (CVE-2013-4547)
WordPress Plugin Attachment File Icons (AF Icons) Cross-Site Request Forgery (1.3)
Oracle JRE CVE-2017-10350 Vulnerability (CVE-2017-10350)
Django Improper Input Validation Vulnerability (CVE-2023-31047)