PMB v7.4.6 was discovered to contain an open redirect vulnerability via the component /opac_css/pmb.php. This vulnerability allows attackers to redirect victim users to an external domain via a crafted URL.
| Software | From | Fixed in |
|---|---|---|
| sigb / pmb | 7.4.6 | 7.4.6.x |