Cross Site Scripting vulnerability found in Zentao allows a remote attacker to execute arbitrary code via the lang parameter