An attacker with admin privileges and access to Translations management functionality may add JS payload to translation values via:
Translation management UI.
Translations downloaded via the Crowdin service may also contain JS strings used for XSS attacks, for a successful attack poisoned translation should be enabled, downloaded, and installed.
Translations uploaded via Upload translation file on the All Languages grid
Workarounds
There are no workarounds that address this vulnerability.