Gentoo Linux Security Advisory GLSA 200711-05 – Tim Brown discovered these multiple issues: the translation module does not properly sanitize the value to the dir parameter; the translation module also does not sanitize the values of the edit and value parameters which it passes to eval() and include(); the log-in command does not validate the URL to redirect users to after logging in; SiteBar also contains several cross-site scripting vulnerabilities. Versions less than 3.3.9 are affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/60740/glsa-200711-05.txt
Source: https://packetstormsecurity.com/files/60740/Gentoo-Linux-Security-Advisory-200711-5.html

