Lack of "current" GET parameter validation during the action of changing a language leads to an open redirect vulnerability.