Description
When an nginx web server implements an HTTP redirect by using the $uri or $document_uri variables within the redirection target location, the resulting configuration may be vulnerable to header injection.
Remediation
Implement the HTTP redirect with $request_uri instead of $uri or $document_uri.
References
Related Vulnerabilities
WordPress Plugin IMPress Listings Cross-Site Scripting (2.0.1)
WordPress Plugin UpdraftPlus WordPress Backup Cross-Site Scripting (1.13.4)
Drupal Core 9.0.x Cross-Site Scripting (9.0.0 - 9.0.14)
WordPress Plugin CMS Tree Page View Cross-Site Scripting (1.2.31)
WordPress Plugin Syndication Links Cross-Site Scripting (1.0.2)