Open Redirect: How Your Trusted Link Sends Users to an Attacker
An open redirect lets an attacker borrow your domain's credibility to bounce victims to phishing pages and steal OAuth tokens. Here is how the unvalidated redirect parameter is abused and how to constrain it.