Search/CVE-2007-1473
CVE

CVE-2007-1473

Cross-site scripting (XSS) vulnerability in framework/NLS/NLS.php in Horde Framework before 3.1.4 RC1, when the login page contains a language selection box, allows remote attackers to inject arbitrary web script or HTML via the new_lang parameter to login.php.

CVSS v3.1
EPSS
5.15%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
Connections
1 relationships
Timeline
disclosure → media coverage
Mar 16, 2007
Disclosure — published as a CVE record. · last revised by NVD Apr 23, 2026