PMB v7.4.6 contains an open redirect vulnerability via the component /opac_css/pmb.php. An attacker can redirect a user to an external domain via a crafted URL and thereby potentially obtain sensitive information, modify data, and/or execute unauthorized operations.
id: CVE-2023-24735
info:
name: PMB 7.4.6 - Open Redirect
author: r3Y3r53
severity: medium
d
...